SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC1.4: CC1.4 Attracting, developing and retaining competent people (COSO principle 4)

The organisation hires, develops and keeps people with the competence its objectives require. Points of focus: policies state the competence expected; competence of staff and outsourced providers is evaluated and shortfalls addressed; mentoring and training support recruitment and retention; succession is planned for roles important to control; backgrounds of staff, contractors and vendor employees are considered before hiring and retaining them; their technical competence is assessed; and ongoing training keeps technical skills current.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 93 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

ISO 27701:2019 · 5 controls

  • 5.5.1 Resources
  • 5.5.2 Competence
  • 6.4 Human resource security
  • 6.4.1 Prior to employment
  • 6.4.2 During employment

ISO/IEC 42001:2023 · 5 controls

  • 7.1 Resources
  • 7.2 Competence
  • A.4 Resources for AI systems
  • A.4.2 Resource documentation
  • A.4.6 Human resources

PCI DSS 4.0 · 5 controls

  • 12.10.4 12.10.4 Periodic training for incident response personnel
  • 12.6.2 12.6.2 Awareness program reviewed annually and updated
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.7.1 12.7.1 Pre-hire screening of personnel with CDE access
  • 6.2.2 6.2.2 Annual secure software training for developers

FedRAMP High · 4 controls

  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • PS-3 Personnel Screening

FedRAMP Moderate · 4 controls

  • AT-2 Literacy Training and Awareness
  • AT-3 Role-Based Training
  • AT-4 Training Records
  • PS-3 Personnel Screening

ISO 22301:2019 · 4 controls

  • 5.1 Leadership and commitment
  • 7.1 Resources
  • 7.2 Competence
  • 8.3.4 Resource requirements

ISO 27002:2022 · 4 controls

  • 6.1 Screening
  • 6.2 Terms and conditions of employment
  • 6.3 Information security awareness, education and training
  • 6.6 Confidentiality or non-disclosure agreements
  • NIST-CSF-GV.RR-03 Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
  • CPS220-10 Designated Risk Management Function
  • CPS220-P43 Designated Compliance Function
  • CPS220-P47 Minimum Assessment Required by the Framework Review

APRA CPS 234 · 3 controls

  • CPS234-15 Information Security Capability
  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P33 Skill of Personnel Providing Control Assurance

C5 (Germany) · 3 controls

  • C5-DEV-04 Safety training and awareness programme regarding continuous software delivery and associated systems, components or tools
  • C5-HR-01 Verification of qualification and trustworthiness
  • C5-HR-03 Security training and awareness programme

CIS Controls v8 · 3 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-16.9 Train Developers in Application Security Concepts and Secure Coding

CMMC 2.0 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

NIST SP 800-181 · 3 controls

  • AEO-10 Education, Training and Awareness
  • AEO-8 Personnel Security

EU AI Act · 2 controls

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 6.1 Screening
  • 6.3 Information security awareness, education and training

NIS2 Directive · 2 controls

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis
  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.2.1e Provide Awareness Training on Advanced Persistent Threat
  • 3.9.1e Enhanced Personnel Screening

NIST SP 800-66 Rev 2 · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-CONTROL-ENV Control Environment
  • ANSSI-HYG-01 Train Operational Teams in Information System Security

APPI · 1 control

  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities
  • ASD37-37 Personnel management (Very Good)
  • AUCDR-IS-6 Information security training and awareness program

DORA · 1 control

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC1.4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 93 it maps to, and the evidence behind each claim, over MCP and REST.