The people responsible for security have the skills to actually do it. This criterion covers hiring (background checks, competency screening), training (annual security training with completion tracking), and performance management (annual reviews). For a small team, auditors understand you may not have a dedicated security staff, but the people handling security controls need to demonstrate they understand what they are doing.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Pre-employment background checks for all staff with system access
Implementation Steps
Require background checks (criminal history, employment verification) before or promptly after hire, document this requirement in your HR onboarding policy
Retain background check completion records; the vendor report or HR confirmation is the evidence, you do not need to retain the detailed results, only confirmation that a check was completed
Ensure background check policy applies to contractors and third parties with privileged system access, not just employees
For jurisdictions where background checks are restricted, document the legal constraint and the compensating control used
Typical Control Annual security awareness training with tracked completion
Implementation Steps
Assign security awareness training to all staff at hire and annually thereafter, use your GRC platform or a dedicated training tool to track completion
Training content should cover phishing awareness, password security, data handling, incident reporting, and acceptable use, tailor to your risk profile
Track completion per user with timestamps; incomplete training after 30 days of due date is a finding auditors flag consistently
Role-specific training for engineers handling production systems should cover secure coding basics and least-privilege principles