← SOC 2 · CC1 — Control Environment

CC1.4 — Competence of personnel

medium traininghr-screening

Requirement

The entity demonstrates a commitment to attract, develop and retain competent individuals, including security awareness training and role-specific competence.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
security awarenesstrainingcompetencetrain
Supporting terms — specificity signals
onboardingannual trainingcertificationskills matrixbackground check

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
CCPA/CPRA 1798.130(a)(6) & Regs 7100 Training for staff who handle privacy inquiries training
ISO 27001 A.6.1 Screening hr-screening
ISO 27001 A.6.3 Information security awareness, education and training training
PCI DSS 4.0.1 12.6 Security awareness programme training
HIPAA 164.308(a)(3)(ii)(B) Workforce clearance procedure (A) hr-screening
GLBA 314.4(e) Security awareness training and qualified security personnel training
NIST CSF 2.0 PR.AT-01 Personnel are provided awareness and training training
NDPA 2023 GAID Art.30 Privacy training and internal sensitisation (GAID 2025) training