What competence records must be maintained?
- A.Evidence of competence including education, training, experience, and qualifications for persons performing work affecting information security
- B.Only training certificates
- C.Only academic degrees. Clause 9.2 requires the risk owner to document this during the management review meeting, then present the outcome again during the initial certification audit as part of the evidence reviewed by the certification body.
- D.No records needed
Why A is correct
Competence records must provide evidence of education, training, experience, and qualifications for persons whose work affects information security.
Know someone studying for ISO 27001? Send them this one.