ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.7 Clear desk and clear screen

ISO 27001 Annex A 7.7 Clear desk and clear screen

What is ISO 27001 Annex A 7.7 – Clear Desk and Clear Screen?

ISO 27001 Annex A 7.7 requires organizations to establish appropriate rules for clear desk and clear screen practices to protect information from unauthorized access, viewing, loss, or disclosure.

The control addresses two common situations:

Clear Desk

Sensitive information should not be left unattended on physical desks or workspaces.

Examples include:

  • Printed customer information
  • Contracts
  • Financial documents
  • Employee records
  • Security reports
  • Passwords or authentication information
  • Product development documents
  • Confidential meeting notes
  • USB drives or other storage media

Clear Screen

Sensitive information should not remain visible on computer screens when the authorized user is away.

Examples include:

  • Customer records
  • Financial information
  • Source code
  • Security dashboards
  • HR information
  • Credentials
  • Internal reports
  • Personal information
  • Confidential business information

Simple Explanation

If someone who is not authorized can see or access sensitive information simply because an employee left it unattended, the organization has a clear desk or clear screen risk.


Why is A.7.7 Important?

Information can be exposed without a hacker breaking into a system.

For example:

An employee leaves a laptop unlocked while going to lunch.

Another person walks past and sees:

  • Customer information
  • Internal emails
  • Security alerts
  • Financial data

Similarly, an employee may leave a confidential customer contract on a desk overnight.

A person with physical access to the office may read or photograph it.

These are information-security risks even though:

  • No account was hacked
  • No firewall was bypassed
  • No malware was installed
  • No database was compromised

Simple Principle

Information should not be exposed simply because its authorized user walked away.


What Does ISO 27001 A.7.7 Require?

Organizations should establish and enforce appropriate clear desk and clear screen rules based on:

  • Information classification
  • Business requirements
  • Physical environment
  • Threats
  • Regulatory requirements
  • Customer requirements
  • Remote/hybrid working arrangements
  • Type of information processed

The control does not mean every employee must have a completely empty desk at all times.

It means that sensitive information and assets should be protected when they are unattended.


Clear Desk vs. Clear Screen

AreaClear DeskClear Screen
Main concernPhysical informationElectronic information
ExamplePrinted customer reportCustomer database on screen
Main riskUnauthorized viewing or removalUnauthorized viewing/access
Typical controlSecure storageScreen lock
Relevant locationOffice/workspaceLaptop/desktop
EvidenceInspection recordsDevice/security configuration

Both controls address the same underlying principle:

Prevent unauthorized people from seeing or accessing information when it is unattended.


Activities Required to Implement A.7.7

1. Identify Sensitive Information

Start by determining what information should receive clear desk and clear screen protection.

Examples:

  • Customer information
  • Personally identifiable information (PII)
  • Financial records
  • Employee records
  • Contracts
  • Security information
  • Credentials
  • Source code
  • Product designs
  • Confidential business information
  • Incident records
  • Audit reports

Information classification under A.5.12 can help determine the required level of protection.


2. Define Clear Desk Rules

The organization should define practical requirements.

For example:

Employees should:

  • Store confidential documents securely when unattended
  • Avoid leaving sensitive documents on desks overnight
  • Lock physical records when required
  • Secure laptops and removable media
  • Dispose of confidential documents appropriately
  • Avoid leaving passwords or credentials visible
  • Remove sensitive information from meeting rooms
  • Secure documents when leaving the workspace

3. Define Clear Screen Rules

Employees should be required to protect information displayed on their screens.

Typical requirements include:

  • Lock the screen when leaving the workstation
  • Use automatic screen locking
  • Do not leave sensitive applications open unnecessarily
  • Position screens appropriately
  • Use privacy screens where justified
  • Avoid displaying confidential information where unauthorized people can see it
  • Log out from shared systems where required

A simple rule is:

If you leave your workstation, lock your screen.


4. Configure Automatic Screen Locking

Where technically possible, organizations should configure automatic screen locking.

For example:

  • Windows
  • macOS
  • Linux
  • Mobile devices
  • Virtual desktops

The organization can define an appropriate inactivity period based on its risk and environment.

Automatic locking should complement employee behavior rather than replace it.

Employees should still manually lock their screens whenever leaving their workstation.


5. Protect Printed Information

Printed information can create significant security risks.

Organizations should consider:

  • Secure storage
  • Controlled printing
  • Secure printing/release
  • Appropriate disposal
  • Shredding
  • Document classification
  • Restricted access to printers
  • Removal of documents from printers

Example

An employee prints a customer contract and forgets to collect it.

Another employee later sees the document.

The issue is not that the printer failed.

The issue is that the organization did not adequately protect information during printing and handling.


6. Secure Printers and Scanners

Printers and multifunction devices can contain sensitive information.

Organizations should consider:

  • Physical location
  • Access to printed documents
  • Secure print release
  • Storage of scanned documents
  • Administrative access
  • Disposal of printed material
  • Device storage where applicable

For highly sensitive environments, employees may need to authenticate before documents are released from a printer.


7. Dispose of Sensitive Information Securely

Sensitive documents should not simply be thrown into a normal waste bin.

Appropriate disposal may include:

  • Cross-cut shredding
  • Secure document disposal services
  • Approved destruction processes
  • Secure disposal of removable media

The method should be appropriate to the sensitivity of the information.


8. Apply Clear Desk and Clear Screen to Meeting Rooms

Sensitive information can also be exposed in meeting rooms.

For example:

A team discusses a new product and leaves:

  • Product plans
  • Customer information
  • Printed reports
  • Whiteboard diagrams

behind after the meeting.

The organization should consider:

  • Clearing whiteboards
  • Removing printed documents
  • Collecting meeting notes
  • Locking screens
  • Removing removable media
  • Securing confidential presentations

9. Consider Remote and Hybrid Working

Clear desk and clear screen requirements should not stop at the office door.

Employees working remotely may work from:

  • Home
  • Hotels
  • Coworking spaces
  • Airports
  • Customer locations
  • Cafes
  • Shared accommodation

Risks include:

  • Family members seeing information
  • Someone viewing a laptop screen
  • Printed documents being left at home
  • Lost notebooks
  • Unsecured home printers
  • Screen visibility in public places

Employees should therefore receive practical guidance for remote working.


Startup Example – SaaS Company

Consider a 50-person SaaS company handling customer information.

Employees use:

  • Laptops
  • Google Workspace
  • Slack
  • CRM
  • AWS
  • HR systems
  • Finance systems

The company establishes the following rules:

Clear Desk

  • Confidential documents must not be left unattended.
  • Printed customer/employee information must be securely stored.
  • Sensitive documents must be securely destroyed.
  • Employees must remove confidential documents from meeting rooms.

Clear Screen

  • Employees must lock their screen when leaving the workstation.
  • Automatic screen locking is enabled.
  • Sensitive information should not be displayed where unauthorized people can see it.
  • Privacy screens are used for specific high-risk roles where appropriate.

Remote Work

  • Employees must protect screens from unauthorized viewing.
  • Sensitive documents should not be printed unless necessary.
  • Company laptops must be locked when unattended.
  • Confidential information should not be discussed in public places where it can be overheard.

Simple Startup Workflow

Classify Information

↓

Identify Sensitive Information

↓

Define Clear Desk Rules

↓

Define Clear Screen Rules

↓

Configure Technical Controls

↓

Train Employees

↓

Monitor / Inspect

↓

Report Issues

↓

Improve


Clear Desk and Clear Screen Risk Examples

SituationRiskPossible Control
Laptop left unlockedUnauthorized viewingScreen lock
Customer report left on deskInformation disclosureSecure storage
Confidential document left at printerUnauthorized accessSecure print
Password written on paperCredential exposurePassword manager
Whiteboard contains customer informationInformation disclosureClear after meeting
USB drive left unattendedData loss/theftSecure storage
Screen visible through office windowUnauthorized viewingScreen positioning/privacy screen
Confidential document thrown in normal binInformation disclosureSecure destruction
Employee working in caféShoulder surfingScreen positioning/privacy screen

Clear Desk and Clear Screen Policy Example

A simple policy can state:

Employees must protect confidential and sensitive information from unauthorized viewing, access, loss, or disclosure when their workstation or workspace is unattended.

Employees must lock their computer screens when leaving their workstations and must securely store sensitive physical information when it is not actively being used.

Confidential documents must not be left unattended on desks, printers, meeting rooms, or other publicly accessible areas.

Sensitive information must be securely disposed of when no longer required.

Employees working remotely must apply equivalent security precautions appropriate to their environment.

The exact wording should be adapted to the organization’s environment and risk.


Audit Evidence for A.7.7

An auditor may expect evidence that the organization has both defined and implemented clear desk and clear screen requirements.

Policies and Procedures

  • Clear Desk and Clear Screen Policy
  • Information Classification Policy
  • Acceptable Use Policy
  • Records Management Procedure
  • Secure Disposal Procedure
  • Remote Working Policy

Technical Evidence

  • Screen-lock configuration
  • Endpoint management configuration
  • Device security policies
  • Mobile device configuration
  • Group Policy / MDM configuration where applicable

Operational Evidence

  • Security awareness training
  • Employee acknowledgement
  • Physical security inspection records
  • Clear desk inspection checklist
  • Secure disposal records
  • Shredding certificates where applicable
  • Security incident records

Other Evidence

  • Printer configuration
  • Secure print configuration
  • Privacy screen deployment records where relevant
  • Remote working guidance
  • Internal awareness communications

Clear Desk Inspection Checklist

Organizations can periodically perform a simple inspection.

CheckYes/No
Confidential documents are not left unattended
Sensitive information is stored securely
Screens are locked when workstations are unattended
Passwords are not visibly written down
Removable media is secured
Meeting rooms are cleared after use
Whiteboards containing sensitive information are cleared
Printers do not contain unattended confidential documents
Sensitive waste is securely disposed of
Remote-working requirements are communicated

The frequency of inspections should be determined according to risk.


Audit Checklist

An ISO 27001 auditor may ask:

Policy

  • Does the organization have clear desk and clear screen requirements?
  • Are the requirements appropriate to the organization’s risks?
  • Are employees aware of the requirements?

Clear Desk

  • How are confidential documents protected?
  • What happens when employees leave their desks?
  • How are sensitive documents stored?
  • How are confidential documents destroyed?

Clear Screen

  • Are employees required to lock their screens?
  • Is automatic screen locking configured?
  • How are sensitive screens protected from unauthorized viewing?

Printing

  • How are confidential documents handled after printing?
  • Are printers located in appropriate areas?
  • Is secure printing used where necessary?

Remote Work

  • Do clear desk and clear screen requirements apply to remote workers?
  • How are employees instructed to protect information outside the office?

Monitoring

  • Does the organization perform physical security inspections?
  • Are violations recorded and addressed?
  • Are recurring problems identified and improved?

Common Mistakes in Implementing A.7.7

1. Having a Policy but No Technical Control

The policy says:

“Employees must lock their screens.”

But no automatic screen lock exists and there is no evidence of enforcement.

Better approach:

Combine awareness with technical configuration where practical.


2. Focusing Only on Desks

Organizations sometimes think clear desk means only removing papers from desks.

The control also includes:

  • Screens
  • Meeting rooms
  • Printers
  • Whiteboards
  • Removable media
  • Workspaces
  • Remote locations

3. Ignoring Remote Workers

A clear desk policy that applies only to the office is incomplete for a hybrid organization.

Better approach:

Extend the principles to home and other approved remote-working environments.


4. Leaving Documents at Printers

Employees may print sensitive information and forget to collect it.

Better approach:

Use secure print release for sensitive information where appropriate.


5. Writing Passwords on Paper

Employees may write passwords on sticky notes or notebooks.

Better approach:

Use an approved password manager and security awareness training.


6. Treating Every Document as Highly Confidential

Not every piece of paper requires the same level of protection.

Better approach:

Use information classification and risk to determine the appropriate controls.


7. No Secure Disposal Process

A company may protect documents while they are being used but throw them into an ordinary waste bin afterward.

Better approach:

Define and implement secure disposal requirements.


8. Performing Inspections Only Before the Audit

A physical inspection performed once just before certification does not demonstrate an effective ongoing process.

Better approach:

Perform periodic, risk-based checks and maintain records.


Practical Startup Implementation Model

A startup can implement A.7.7 without creating unnecessary bureaucracy.

Step 1 – Identify

Identify sensitive information that could be exposed through desks, screens, printers or workspaces.

Step 2 – Classify

Use the organization’s information classification scheme.

Step 3 – Define

Create clear desk and clear screen rules.

Step 4 – Configure

Implement technical controls such as automatic screen locking.

Step 5 – Educate

Train employees and contractors where relevant.

Step 6 – Apply

Apply the requirements to office, remote and hybrid working.

Step 7 – Inspect

Perform periodic checks based on risk.

Step 8 – Correct

Address violations and recurring weaknesses.

Step 9 – Improve

Update requirements when the organization’s risks or working model change.

Simple Model

Identify → Classify → Define → Configure → Educate → Apply → Inspect → Improve


Policy vs. Process vs. Evidence

ElementExample
PolicySensitive information must not be left exposed when unattended.
ProcessEmployees lock screens, secure documents and securely dispose of sensitive information.
Technical ControlAutomatic screen lock and endpoint management.
EvidencePolicy, training records, configuration evidence, inspection records and disposal records.

Remember:

A policy tells people what is expected. A process explains how it is performed. Evidence demonstrates that it is actually happening.


Relationship With Other ISO 27001 Controls

A.7.7 connects with several other Annex A controls.

ControlRelationship
A.5.10 Acceptable UseDefines appropriate use of information and assets
A.5.12 Classification of InformationHelps determine what information requires stronger protection
A.5.13 Information LabellingHelps identify sensitive information
A.5.14 Information TransferProtects information during transfer
A.5.15 Access ControlSupports prevention of unauthorized access
A.5.18 Access RightsControls who can access information
A.5.33 Protection of RecordsProtects important records
A.5.34 Privacy and Protection of PIIProtects personal information
A.6.3 Awareness and TrainingEducates employees about clear desk and screen requirements
A.6.7 Remote WorkingExtends security requirements to remote environments
A.6.8 Event ReportingEnables reporting of information exposure
A.7.6 Working in Secure AreasEstablishes secure working practices in restricted areas
A.7.8 Equipment Siting and ProtectionProtects equipment from physical exposure
A.7.9 Security of Assets Off-PremisesProtects assets outside organizational premises
A.8.1 User Endpoint DevicesProtects laptops, desktops and other endpoint devices

A.7.6 vs A.7.7

These controls are closely related but have different purposes.

A.7.6 – Working in Secure Areas

Focus:

How people work inside areas requiring additional physical security.

A.7.7 – Clear Desk and Clear Screen

Focus:

Preventing information from being exposed when workspaces or screens are unattended.

For example:

An employee working in a restricted server room is covered by A.7.6.

The same employee leaving a laptop unlocked while walking away creates a A.7.7 clear-screen issue.


Useful Resources and Draft Documents

Organizations implementing A.7.7 may create:

  1. Clear Desk and Clear Screen Policy
    [Insert Draft Document Link]
  2. Information Classification Policy
    [Insert Draft Document Link]
  3. Secure Document Handling Procedure
    [Insert Draft Document Link]
  4. Secure Disposal Procedure
    [Insert Draft Document Link]
  5. Clear Desk Inspection Checklist
    [Insert Draft Document Link]
  6. Physical Security Inspection Checklist
    [Insert Draft Document Link]
  7. Secure Printing Procedure
    [Insert Draft Document Link]
  8. Remote Working Security Policy
    [Insert Draft Document Link]
  9. Information Security Awareness Training Material
    [Insert Draft Document Link]
  10. Security Incident Report Form
    [Insert Draft Document Link]

Questions an Auditor May Ask

“What is your clear desk and clear screen policy?”

Show the documented policy and explain how it applies to employees and relevant third parties.

“How do you ensure employees lock their screens?”

Explain the combination of user awareness and technical controls such as automatic screen locking.

“How do you protect printed confidential information?”

Explain secure storage, handling, printing and disposal processes.

“What happens to confidential documents when they are no longer required?”

Show the secure disposal procedure and relevant evidence.

“Does this apply to remote workers?”

Explain how the requirements are communicated and applied outside the office.

“How do you know employees are following the policy?”

Provide evidence such as:

  • Awareness training
  • Physical inspections
  • Security reviews
  • Corrective actions
  • Incident records

Startup-Focused Quick Summary

For a startup, A.7.7 can often be implemented with a few simple rules:

1. Lock your screen when you walk away.

2. Do not leave confidential documents unattended.

3. Store sensitive physical records securely.

4. Do not leave confidential documents at printers.

5. Clear meeting rooms and whiteboards after sensitive discussions.

6. Secure laptops and removable media.

7. Dispose of confidential information securely.

8. Protect screens from unauthorized viewing.

9. Apply the same principles when working remotely.

10. Train employees and periodically check compliance.


Startup-Focused Final Takeaway

ISO 27001 Annex A 7.7 is one of the simplest controls to understand but one that can easily be overlooked.

A sophisticated cybersecurity environment does not eliminate basic physical information exposure.

A company can have:

  • MFA
  • EDR
  • Firewalls
  • SIEM
  • Encryption
  • Cloud security

and still expose confidential information because an employee leaves a sensitive document on a desk or a laptop unlocked.

The practical objective of A.7.7 is therefore simple:

When people are not actively using sensitive information, that information should not be left unnecessarily exposed.

For a startup, the implementation can be straightforward:

Identify Sensitive Information → Define Clear Desk Rules → Define Clear Screen Rules → Configure Technical Controls → Train Employees → Apply to Remote Work → Inspect → Improve

The objective is not to create a culture where employees cannot work comfortably.

The objective is to create a simple security habit:

If you walk away, secure the information.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *