Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 7.7

Clear Desk and Clear Screen: A Practical Implementation Guide

Reduce casual exposure, loss and misuse of information when workspaces or devices are unattended.

This control concerns clear-desk rules for papers and removable media and clear-screen rules for information-processing facilities.

Practical interpretation: The rule should match work patterns and information sensitivity. It includes shared spaces, home offices, meeting rooms, printing, whiteboards and locked screens.

What should the control achieve?

  • Sensitive material is secured when unattended.
  • Screens lock automatically and on user departure.
  • Printing and disposal follow controlled processes.
  • Workplace checks reinforce behavior proportionately.

Step-by-step implementation

1

Define scope and sensitivity

Set rules for offices, reception, meeting rooms, remote work and high-risk areas.

2

Provide secure storage

Make lockers, cabinets and secure bins accessible.

3

Configure screens

Use automatic lock, short timeout for sensitive areas and privacy screens where needed.

4

Control printing and boards

Use secure release, immediate collection and end-of-meeting cleanup.

5

Communicate practical routines

Include end-of-day and temporary absence expectations.

6

Monitor and improve

Use respectful walkthroughs, incident trends and targeted coaching.

What this could look like in practice

A finance team uses secure print release and locked cabinets. Screens lock after five minutes, and employees lock manually when leaving. Evening checks record exposed sensitive items without photographing personal content.

ActivityPractical implementationEvidence
Temporary absenceUser locks screen and secures Restricted papers.Observation
PrintingBadge release prevents unattended output.Printer log
Meeting roomWhiteboards and documents are cleared after use.Room checklist
DisposalSensitive paper enters locked shredding bins.Destruction record

Implementation evidence

  • Clear-desk policy
  • Screen-lock configuration
  • Secure-storage provision
  • Print settings
  • Disposal contract
  • Awareness material
  • Walkthrough results
  • Corrective actions

Useful metrics

  • Devices meeting lock baseline
  • Exposed-item findings
  • Uncollected sensitive print jobs
  • Repeated team findings

Common mistakes

  • Creating rules without providing storage.
  • Overly long screen timeouts.
  • Ignoring whiteboards and meeting rooms.
  • Taking invasive photos during inspections.
  • Applying office rules poorly to remote workers.

Questions an auditor may ask

  • What must be secured and when?
  • How are screens configured?
  • Show secure printing and disposal.
  • How are checks conducted fairly?
Implementation test: Inspect representative workspaces during lunch and after hours and verify papers, media, screens, printing and boards are protected.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.