A7.7 Clear desk and clear screen
3 min read
ISO 27001 A7.7 Clear desk and clear screen emphasize the importance of maintaining a clean and secure workspace, both physically and digitally. This control ensures sensitive information isn’t left exposed on desks or screens where unauthorized personnel could access it.
A cluttered desk or an unlocked screen might seem harmless, but in reality, it’s an open invitation for data leakage, especially in shared offices or public environments. Whether it’s confidential printouts, sticky notes with passwords, or an unattended screen, the risk is real.
This control is designed to reduce the likelihood of accidental or intentional data exposure, especially during off-hours or when workspaces are unattended.
Implementation Guide #
- Clear Desk Policy
- Require that all documents containing sensitive or confidential data be securely stored when not in use.
- Lock filing cabinets, drawers, or storage units containing sensitive materials.
- Avoid leaving notes, post-its, or printouts containing passwords or personal data in plain sight.
- Clear Screen Policy
- Enforce automatic screen lock settings after a short period of inactivity (e.g., 5–10 minutes).
- Encourage manual screen locking (e.g., Windows + L) when stepping away from the desk.
- Position monitors to minimize shoulder surfing or install privacy screens if needed.
- Secure Printing Practices
- Implement pull printing or secure printing systems where users must authenticate before collecting printouts.
- Set printers to avoid automatic printing of sensitive materials unless authorized.
- Clean-Up Routine
- Incorporate desk checks during end-of-day routines or spot audits.
- Use signage or desk reminders to reinforce the policy.
- Training and Awareness
- Educate staff regularly about the risks of unattended data.
- Include the policy in onboarding and refresh training programs.
Compliance with ISO 27001 A.7.7 #
To comply:
- Define and enforce clear desk and clear screen policies.
- Document procedures and include responsibilities.
- Apply technical controls for screen locking and secure printing.
- Regularly monitor and reinforce compliance through training and audits.
How to Pass an Audit #
Documents to Prepare:
- Clear Desk and Clear Screen Policy
- Employee awareness/training materials
- Print management system records (if applicable)
- Screen lock configuration logs or screenshots
- Internal audit or spot check records
What the Auditor Will Check:
- Is the policy documented and enforced?
- Do staff follow screen locking and desk cleanup procedures?
- Are devices configured with inactivity-based lockouts?
- Is there evidence of training and awareness?
Common Mistakes #
- No documented policy—leading to inconsistent practices.
- Employees unaware of expectations.
- No screen lock settings enforced.
- Sensitive information left visible during off-hours or unattended.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.7.7 Clear Desk and Clear Screen | Preventive, Physical, Technical |
| Purpose | To prevent unauthorized access or disclosure of sensitive information left unattended |
| Applicability | All employees, contractors, remote/hybrid workers |
| ISO 27001 Domains | Physical and Environmental Security |
Related Documents or Templates #
- Clear Desk and Clear Screen Policy Template (Word)
- Staff Awareness Training Slide Deck (PPT)
- End-of-Day Checklist (Excel or Word)
- Print Release System Configuration Guide (PDF)
- Desktop Locking Configuration SOP (Word)
Good security habits start with small actions. A clean desk and a locked screen are simple, effective defenses against prying eyes and accidental leaks. It’s not just about neatness—it’s about protecting your organization’s data every single day.
Tip: Create a slogan for your workplace:
“Clear desk, clear mind. Locked screen, secure data.”