Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?
Clause 7.2 (Competence) requires the organization to:
''determine the necessary competence of person(s) doing work under its control that affects its information security performance;''
''ensure that these persons are competent on the basis of appropriate education, training, or experience;''
''retain appropriate documented information as evidence of competence.''
This makes holding up-to-date records on training, skills, experience, and qualifications (D) the correct answer. Option A is irrelevant to competence. Option B is incorrect since ISO does not require Foundation-level training --- competence is context-based. Option C is related to compliance but does not ensure individual competence.
Thus, the verified correct answer is D.
Kati
5 months agoJoaquin
5 months agoToi
6 months agoMohammad
6 months agoDarrin
6 months agoLeatha
6 months agoKristel
7 months agoNikita
7 months agoChaya
7 months agoStephen
7 months agoKatheryn
7 months agoMiles
8 months agoNatalya
8 months agoMalissa
8 months ago