ISO/IEC 27001:2022 Annex A · Control 7.7
Clear Desk and Clear Screen: A Practical Implementation Guide
Reduce casual exposure, loss and misuse of information when workspaces or devices are unattended.
This control concerns clear-desk rules for papers and removable media and clear-screen rules for information-processing facilities.
What should the control achieve?
- Sensitive material is secured when unattended.
- Screens lock automatically and on user departure.
- Printing and disposal follow controlled processes.
- Workplace checks reinforce behavior proportionately.
Step-by-step implementation
Define scope and sensitivity
Set rules for offices, reception, meeting rooms, remote work and high-risk areas.
Provide secure storage
Make lockers, cabinets and secure bins accessible.
Configure screens
Use automatic lock, short timeout for sensitive areas and privacy screens where needed.
Control printing and boards
Use secure release, immediate collection and end-of-meeting cleanup.
Communicate practical routines
Include end-of-day and temporary absence expectations.
Monitor and improve
Use respectful walkthroughs, incident trends and targeted coaching.
What this could look like in practice
A finance team uses secure print release and locked cabinets. Screens lock after five minutes, and employees lock manually when leaving. Evening checks record exposed sensitive items without photographing personal content.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Temporary absence | User locks screen and secures Restricted papers. | Observation |
| Printing | Badge release prevents unattended output. | Printer log |
| Meeting room | Whiteboards and documents are cleared after use. | Room checklist |
| Disposal | Sensitive paper enters locked shredding bins. | Destruction record |
Implementation evidence
- Clear-desk policy
- Screen-lock configuration
- Secure-storage provision
- Print settings
- Disposal contract
- Awareness material
- Walkthrough results
- Corrective actions
Useful metrics
- Devices meeting lock baseline
- Exposed-item findings
- Uncollected sensitive print jobs
- Repeated team findings
Common mistakes
- Creating rules without providing storage.
- Overly long screen timeouts.
- Ignoring whiteboards and meeting rooms.
- Taking invasive photos during inspections.
- Applying office rules poorly to remote workers.
Questions an auditor may ask
- What must be secured and when?
- How are screens configured?
- Show secure printing and disposal.
- How are checks conducted fairly?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.