8.3 People, Skills, and Competencies
Key Takeaways
- People, skills and competencies is the human capacity required to make decisions and complete activities — not a headcount line and not the committee list.
- Define skill requirements per role and map those skills to the domains and objectives the role supports.
- The component includes internal staff, contractors, and vendors; outsourced hands still need the skills the objective requires.
- The closest objective is APO07 Managed Human Resources; ISACA teaching under this component includes SFIA-style skill mapping.
- The exam trap is confusing this component with organizational structures: bodies and roles versus the skills inside them.
Quick Answer: People, skills and competencies is the human capacity required to make correct decisions and to complete activities. Define skill requirements per role, map those skills to domains and objectives, and include internal staff, contractors, and vendors. This is not headcount. A bank that buys a SIEM with no analysts has filled services, infrastructure and applications and left this slot empty. The exam trap is mixing this component with organizational structures — roles and bodies versus the skills inside them. APO07 Managed Human Resources is the closest objective; SFIA-style skill mapping is how ISACA teaching often expresses the component.
You already know from Chapter 6 that this component is “the human capacity required to make correct decisions and to complete activities successfully.” That one-liner is exam-ready. This section unpacks it so you do not spend it on the wrong slot.
Competency is not headcount
A 40-person “security team” that cannot tune a detection rule is not a people component. It is a roster. COBIT is asking a different question: can the humans who must perform this objective’s activities actually do so? That is skill and competency, not FTE.
Work the component in this order:
- Name the role the objective needs (this touches organizational structures — the seat).
- Define the skill requirements for that role (this component — what the person in the seat must be able to do).
- Map those skills to domains and objectives so you can see that APO12, DSS05, and MEA01 do not all pretend the same generalist is enough.
- Cover every source of labor — employees, contractors, and vendor staff who act in the process.
- Close the gap with hire, train, contract, or redesign the activity. Do not close it by buying another tool.
Headcount without that sequence is how Larkspur Bank, later in this section, owns a SIEM and still has no one who can investigate an alert.
Skill requirements per role, mapped to objectives
Do not write a single enterprise-wide “we need IT people” sentence and call the component done. Requirements are per role and per objective cluster.
| Role (structure slot) | Skills this component must specify | Objectives that need them |
|---|---|---|
| Change approver | Risk judgment, service-impact reading, ability to refuse a bad change | BAI06, DSS03 |
| Risk analyst | Scenario analysis, control design, reporting that a board can use | APO12, EDM03, MEA02 |
| Incident responder | Triage, comms under pressure, tool operation | DSS02, DSS05 |
| Process owner | Metric reading, improvement facilitation | MEA01 plus the owned objective |
| Vendor operator | The same operational skills the in-house role would have needed | Whatever was outsourced |
The left column is organizational structures (who may decide or act). The middle column is people, skills and competencies. If you put “CAB exists” in the middle column, you have slipped slots. If you put “CISSP headcount = 4” in the left column, you have also slipped slots. Four certificates do not create a decision-making body. A named body does not create four competent people.
Mapping to domains keeps the inventory honest. EDM needs people who can challenge management. APO needs planners, architects, risk and security specialists, and relationship managers. BAI needs builders and testers. DSS needs operators. MEA needs people who can monitor without being captured by the teams they assess. One “IT generalist” pool is not a map.
Internal staff, contractors, and vendors
The component does not stop at the employee directory. If a managed-security provider investigates alerts, their analysts are in this slot for DSS02 and DSS05. If a system integrator configures the ERP, their competencies are in this slot for BAI. If a contractor sits in the CAB with a vote, their judgment is in this slot for BAI06.
Outsourcing moves where the people sit. It does not delete the need for the skills. A contract that says “vendor shall provide competent staff” without defining the skills is a principles, policies and frameworks document that still leaves this component empty. Holistic again: the service is bought (next section), the RACI names the vendor (structures), and nobody checked whether the night-shift analysts can actually perform the activity.
APO07 and SFIA-style mapping
The management objective that most directly runs this component is APO07 Managed Human Resources — acquire, motivate, develop, and retain people, including the skills the other 39 objectives consume. Do not say APO07 is the component. APO07 is an objective. The component is the human capacity described on every objective’s card. APO07 is how the enterprise typically manages that capacity across the system.
ISACA’s teaching under this component includes SFIA-style skill mapping (Skills Framework for the Information Age): levels of responsibility and professional skills mapped onto roles. Recognize the idea. Do not claim SFIA is a COBIT domain, a seventh principle, or a replacement for the 40 objectives. Do not invent an official Foundation list of “the 12 SFIA codes you must recite.” The exam-useful claim is smaller: skill requirements are defined, leveled, and mapped to roles and objectives, and SFIA is a commonly taught way to do that mapping.
Scenario: Larkspur Bank buys a SIEM
Larkspur Bank’s board funds a SIEM after an audit finding on DSS05. The platform is implemented on time. No analysts are hired or trained. The vendor’s onboarding week ends. Alerts page an on-call infrastructure engineer who silences them. Six months later the dashboard is green because thresholds were raised.
Services, infrastructure and applications is populated. Processes may even have a “monitor SIEM” activity. Organizational structures may show a “SOC lead” box that is vacant or filled by someone whose real job is network operations. The missing component is people, skills and competencies. Competency was never specified per role, never mapped to DSS05/DSS02, and never extended to the vendor’s remaining retainers. Headcount in “IT security” went up by one platform owner. The objective still cannot be performed.
The repair is a skill definition (detect, hunt, tune, investigate, communicate), a map to the objectives, and a fill plan that can mix employees, contractors, and the MSSP — with evidence that those humans actually have the skills. Buying a second platform repeats the mistake.
Exam traps for this component
- Structures versus skills: Organizational structures = decision-making entities and roles. This component = the skills and competencies of the people (and vendors) who occupy or support those roles. That is the highest-yield trap in this section.
- Headcount equals competency: Rosters and requisitions are not the component.
- Employees only: Contractors and vendors are in scope.
- APO07 is the only place skills matter: APO07 manages the resource. Every objective still has this slot.
- The tool will skill the team: That confuses this component with services, infrastructure and applications.
How items are written
- SIEM / tool / platform with nobody who can run it → this component.
- “We created a SOC steering committee” → structures, not skills, unless the stem also staffs competent people.
- Staff + contractors + vendors → all in this slot.
- SFIA → a mapping method under this component, not a new COBIT domain.
- Headcount without skill requirements → reject as a complete answer.
Once you can separate the seat from the skill, the last component is easy: the machine the skilled person sits in front of.
Larkspur Bank implements a SIEM on schedule but has no analysts who can tune detections or investigate alerts. Which component is missing?
How does people, skills and competencies differ from organizational structures on a COBIT 2019 item?