Skip to content

Competence & people

An ISMS depends on people knowing what they’re responsible for and being competent to do it. Keel covers the people side with a competence matrix, a staff-facing security digest, and a RACI matrix.

In Competence, record each person’s required competence with the basis for it — education, training, experience, or certification — a status of Met / In progress / Gap, the evidence, and an expiry date for certifications. This is the Clause 7.2 requirement: determine the competence security work needs, make sure people have it, and keep proof.

The list view flags gaps, in-progress items, and certifications expiring within 60 days. It pairs with the Training module, which handles awareness training itself.

Staff security rules is a plain-language digest of what everyone needs to do to keep the company and its customers secure, grouped by topic and printable as a one-pager. Share it in onboarding or pin it on your intranet — it backs the security-awareness expectations behind ISO 27001 and SOC 2. It’s a general awareness digest, so adapt it to your own policies rather than treating it as a substitute for them.

In RACI, map who is Responsible, Accountable, Consulted, and Informed across your controls, policies, and risks — the “who owns what” auditors ask for. Each item should have exactly one Accountable owner; Keel warns you when any item has none, and selecting a new Accountable replaces the previous one. Switch between the Controls, Policies, and Risks tabs, and export or print the matrix.