ISO 27001:2022 – Clear Desk and Clear Screen (Annex A 7.7)

by Rahul Savanur

Introduction

The Clear Desk and Clear Screen control (ISO 27001:2022 Clause A.7.7) ensures that sensitive information is protected from unauthorized access in physical work environments. This includes securing documents, removable media, and ensuring that computer screens are locked when unattended.

Clear Desk and Clear Screen

Without enforcing clear desk and clear screen practices, organizations risk accidental data exposure, insider threats, and unauthorized access to confidential information. This control establishes a disciplined approach to workspace security, reducing the likelihood of information leakage and strengthening overall physical and information security posture.

What This Control Is About (Basic Information)

Comply Agent shows:

  • Title: Clear Desk and Clear Screen
  • Control ID: UC-PH-052
  • Category: Physical Security
  • Subcategory: Physical Security Policies and Procedures
  • Version: v1.0

Description

Define and implement clear desk and clear screen practices to protect sensitive information from unauthorized access. This includes securing physical documents, removable media, and ensuring systems are locked when not in use.

Objective

To prevent unauthorized access to sensitive information by ensuring that workspaces, documents, and systems are secured when unattended.

Implementation & Guidance

Comply Agent structures this control as a workplace security enforcement model:

Clear Desk and Clear Screen

1. Establish Clear Desk Policy

Organizations must:

  • Prohibit leaving sensitive documents unattended
  • Require secure storage (locked cabinets, drawers)
  • Define rules for handling printed and physical information

2. Enforce Clear Screen Controls

Implement:

  • Automatic screen lock after inactivity
  • Password/PIN-protected access
  • Secure log-off procedures

3. Secure Physical Workspaces

Ensure:

  • Clean desk practices at end of day
  • No confidential information left in open areas
  • Restricted access to workstations and offices

4. Implement Monitoring and Inspections

Comply Agent highlights:

  • Periodic physical inspections of work areas
  • Spot checks for compliance
  • Logging of inspection findings

5. Conduct Employee Awareness Training

Define:

  • Training on workspace security practices
  • Responsibilities for protecting physical information
  • Awareness of risks (shoulder surfing, unauthorized access)

6. Maintain Compliance Records

Maintain:

  • Policy acknowledgment records
  • Inspection reports
  • Evidence of system-enforced screen locks

Evidence Examples

Comply Agent shows:

  • Clear Desk and Clear Screen Policy document
  • System configuration screenshots for auto-lock settings
  • Physical inspection and audit records of workspaces

Operational Details

Clear Desk and Clear Screen

Comply Agent shows:

  • Frequency: Annually
  • Review Cycle: Annually
  • Owner Role: Facilities Manager
  • Responsible Role: Facilities Manager
  • Automation Score: 40%
  • Last Updated: As per system records

Compliance & Risk Management

Clear Desk and Clear Screen

Comply Agent shows:

  • Status: Not Started
  • Compliance Status: N/A
  • Control Type: Administrative
  • Maturity Level: Level 3
  • Risk Domain: Unauthorized Access to Information
  • Clause Reference: ISO 27001:2022 A.7.7

Framework Mappings

Clear Desk and Clear Screen

Comply Agent shows strong cross-framework alignment:

  • ISO 27001:2022 – A.7.7 (Exact)
  • SOC 2 – CC6.1
  • GDPR – Article 32
  • DORA – Article 10
  • NIST CSF – PR.AC-3, PR.AC-4

Evidence Library

Clear Desk and Clear Screen

Comply Agent shows the required audit evidence:

  • Policy Document – Clear Desk and Clear Screen Policy
  • Screenshots – Screen lock configurations and enforcement
  • Audit Logs (Auto-collected) – System logs for inactivity lock
  • Physical Inspection Records – Workspace audit reports

FAQs: ISO 27001:2022 – Clear Desk and Clear Screen (Annex A 7.7)

1. What is a clear desk and clear screen policy?

It ensures that no sensitive information is left exposed in physical or digital form when workspaces are unattended.

2. Who is responsible for enforcing this control?

Facilities and IT teams enforce policies, while all employees are responsible for complying with workspace security rules.

3. Why is this control important?

It reduces the risk of unauthorized access, data leakage, and insider threats in physical environments.

4. What do auditors expect as evidence?

Auditors look for policies, inspection records, system lock configurations, and employee awareness records.

5. Is automation required for this control?

Automation (like auto screen lock) is strongly recommended but must be supported by policy and user awareness.


Implement ISO Faster with a Complete Documentation System

You're currently viewing a single template. Most ISO implementations require a complete set of policies, procedures, and records. Choose what fits your needs.
BEST FOR single ISO STANDARD

ISO Toolkit for Your Standard

Audit ReadyToolkits

Pick your toolkit from 8 ready-to-use ISO toolkits available: ISO 27001, 9001, 14001, 45001, 22301, 20000, and 42001 (AI Governance).

✔ Complete ISO documentation framework
✔ Policies, procedures, templates, and records
✔ Risk management & internal audit templates
✔ Management Review and Nonconformance
✔ ISO Standard Mapped Implementation Plan

💡 All toolkits come with instant download, one-time payment, and unlimited email & chat support.

View ISO Toolkits Collection →
BEST FOR MULTIPLE ISO STANDARDS

ISO PowerPack Bundle

All 8 ISO Toolkits in One Power Pack

Designed for teams, organizations, and consultants managing multiple ISO implementations across projects and clients.

✔ Unlimited internal and client use
✔ Deliver ISO services from day one
✔ Impress clients and auditors
✔ Skip months of document creation
✔ Grow your consulting business

💡All the benefits of our ISO toolkits combined in one powerful bundle — save over $1,000 compared to buying the toolkits individually.

View ISO PowerPack →