SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
SOC2-CC1.4 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC1.4 Attracting, developing and retaining competent people (COSO principle 4). The organisation hires, develops and keeps people with the competence its objectives require. Points of focus: policies state the competence expected; competence of staff and outsourced providers is evaluated and shortfalls addressed; mentoring and training support recruitment and retention; succession is planned for roles important to control; backgrounds of staff, contractors and vendor employees are considered before hiring and retaining them; their technical competence is assessed; and ongoing training keeps technical skills current.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(3)(ii)(B) Workforce Clearance Procedure (Addressable) (closest match)
- 164.308(a)(5)(i) Security Awareness and Training (Standard) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AT-2 AT-2 Literacy Training and Awareness (closest match)
- NIST800-AT-3 AT-3 Role-based Training (closest match)
- NIST800-PM-2 PM-2 Information Security Program Leadership Role (closest match)
- NIST800-PM-3 PM-3 Information Security and Privacy Resources (closest match)
- NIST800-PM-13 PM-13 Security and Privacy Workforce (closest match)
- NIST800-PS-1 PS-1 Policy and Procedures (closest match)
- NIST800-PS-3 PS-3 Personnel Screening (closest match)
- NIST800-PS-9 PS-9 Position Descriptions (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records