Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?
Clause 7.2 (Competence) requires the organization to:
''determine the necessary competence of person(s) doing work under its control that affects its information security performance;''
''ensure that these persons are competent on the basis of appropriate education, training, or experience;''
''retain appropriate documented information as evidence of competence.''
This makes holding up-to-date records on training, skills, experience, and qualifications (D) the correct answer. Option A is irrelevant to competence. Option B is incorrect since ISO does not require Foundation-level training --- competence is context-based. Option C is related to compliance but does not ensure individual competence.
Thus, the verified correct answer is D.
Kati
2 months agoJoaquin
2 months agoToi
3 months agoMohammad
3 months agoDarrin
3 months agoLeatha
3 months agoKristel
3 months agoNikita
4 months agoChaya
4 months agoStephen
4 months agoKatheryn
4 months agoMiles
4 months agoNatalya
5 months agoMalissa
5 months ago