Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC1.4Commitment to attract, develop, and retain competent individualsSOC 2Control Environment

Official Requirement

The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

The people responsible for security have the skills to actually do it. This criterion covers hiring (background checks, competency screening), training (annual security training with completion tracking), and performance management (annual reviews). For a small team, auditors understand you may not have a dedicated security staff, but the people handling security controls need to demonstrate they understand what they are doing.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Pre-employment background checks for all staff with system access

Implementation steps

  1. Document the background check requirement in the hiring policy or HR onboarding checklist
  2. Collect and retain completion confirmation for each hire, auditors will sample new hires from the audit period
  3. Extend the requirement to any contractor who receives production server or network access

Tools / systems

Evidence artifacts

Evidence frequency: Per hire; auditors sample from hire population during audit period

Annual security awareness training with tracked completion

Implementation steps

  1. Schedule annual training and track completion in a spreadsheet or your GRC tool, every employee must have a completion date for the current period
  2. If using self-administered training (slides and quiz), retain the completion certificate or quiz result per person
  3. New hires must complete training within 30 days of start date, not only at the annual cycle

Tools / systems

Evidence artifacts

Evidence frequency: Annual; log maintained with each completion; auditors sample from roster