Awareness can be linked to competence in the standard, as a person cannot be competent if they are not aware of their ISMS roles and responsibilities. As per the standard, any person working in the organisation must be aware of the information security policy that is in force at the time or a new one must be communicated as per clause 5.2. They must know how much they are contributing to the effectiveness of the ISMS and what this improved efficiency will bring to the information security performance.
Also, the person working under the organisation's control must be aware of the consequences if they are not conforming to the ISMS requirements.