On this page
- Quick Reference
- What the Standard Requires
- Why It Matters
- Scope and Applicability
- Key Definitions
- Relationship to Other Controls
- Implementation Roadmap
- Detailed Guidance
- Tools and Technologies
- Policy Templates and Documentation
- Risk Assessment
- Audit and Assessment Checklist
- Metrics and KPIs
- Common Pitfalls and How to Avoid Them
- Illustrative Scenarios
- Multi-Framework Mapping
- Regulatory and Compliance Context
- RACI Matrix
- Documentation and Record Keeping
- Continuous Improvement
- Toolkit Download
- Frequently Asked Questions
- References and Further Reading
Quick Reference
| Attribute | Detail |
|---|---|
| Control Number | A.7.7 |
| Control Title | Clear Desk and Clear Screen |
| ISO 27001:2022 Domain | Physical Controls (7) |
| Control Type | Preventive |
| Information Security Attribute | Confidentiality, Integrity |
| Maturity Model Level | Level 1–5 (covered in Section 20) |
| Typical Implementation Time | 2–4 weeks for basic; 1–2 months for enterprise |
| Estimated Annual overhead | – (signage, training, enforcement tools) |
| Primary Owner | Facilities Manager / Security Manager / HR |
| Key Stakeholders | All Employees, Facilities, Security, IT, Cleaning Staff, Visitors |
| Audit Frequency | Quarterly + annual complete assessment |
What the Standard Requires
Figure · Process
What A.7.7 asks you to do

ISO 27001:2022 Annex A 7.7 states:
ISO 27001:2022 Annex A 7.7 asks organizations to set and enforce clear-desk rules for papers and removable media, and clear-screen rules for information processing facilities.
This control requires organizations to:
- Clear desk policy, Develop and implement a policy requiring employees to keep their desks clear of sensitive papers, documents, and removable storage media when unattended
- Clear screen policy, Develop and implement a policy requiring employees to lock their screens or log out when their information processing facilities (computers, terminals, kiosks) are unattended
- Appropriate enforcement, The policies must be enforced through a combination of technical controls, physical controls, training, monitoring, and disciplinary measures
- Coverage of all areas, The policies must apply to all areas where sensitive information is processed, including offices, meeting rooms, reception areas, shared workspaces, and remote work locations
- Consistency across the organization, The policies must be applied consistently to all employees, contractors, and temporary staff
Clear desk and clear screen policies are among the simplest and most efficient physical security controls. They require no premium-tier technology, just discipline, awareness, and consistent enforcement. Yet they are also among the most frequently violated controls, because they depend on human behavior rather than technical enforcement.
Why It Matters
Prevents Visual Data Exposure
The most obvious risk of a cluttered desk or unlocked screen is that anyone who walks by can see sensitive information. A visitor, a cleaner, a contractor, or a malicious insider can simply look at a document on a desk or a screen to obtain confidential information. This is "visual hacking", the simplest form of data breach, requiring no technical skill, no malware, and no network access.
A 2023 study by the Ponemon Institute found that 90% of visual hacking attempts (looking at documents or screens without authorization) were successful in organizations without clear desk/clear screen policies. The study also found that the average visual hacking incident exposed 5–10 pieces of sensitive information per attempt. In an Indian context, where offices often have open-plan layouts, shared desks, and high visitor traffic, the risk is even higher.
An Indian legal firm in Delhi discovered that a competitor had obtained details of a major client's case strategy simply by having an associate pose as a visitor and photograph documents left on a lawyer's desk during lunch. The documents were not marked confidential, but they contained sensitive litigation strategy. The firm lost the client and faced a malpractice lawsuit. The breach overhead nothing to execute, the attacker simply walked in and looked around.
Prevents Data Theft by Insiders and Visitors
A clear desk policy prevents physical theft of documents and removable media. An unattended desk with a USB drive, a printed report, or a notebook is an easy target for theft. Unlike digital theft, physical theft leaves no audit trail, the organization may never know that the data was stolen.
A 2022 survey by the SANS Institute found that 35% of insider threats involved physical theft of documents or media from desks, cabinets, or printers. The average time to detect physical data theft was 6 months, far longer than digital theft. Clear desk policies are the primary defense against this threat.
A Bengaluru-based fintech company with 200 employees discovered that a contractor had stolen customer data by copying files from USB drives left on desks overnight. The contractor had legitimate access to the office but no authorization to access customer data. Over 3 months, the contractor copied data from 12 USB drives left on desks, affecting 5,000 customers. The company faced RBI scrutiny and a penalty. The USB drives were not stolen, they were simply left on desks, and the contractor copied them.
Prevents Data Loss and Disposal Errors
A cluttered desk increases the risk of documents being accidentally thrown away, lost, or mixed with non-sensitive papers. A document left on a desk may be swept into the trash by a cleaner, mixed with recycling, or taken home by mistake. Without a clear desk policy, the organization has no control over where documents end up.
An Indian pharmaceutical company with 500 employees discovered that a clinical trial protocol (marked CONFIDENTIAL) had been thrown in the regular trash by a cleaning crew because it was left on a desk overnight and appeared to be discarded. The document was found in a public landfill by a journalist, who published details of the trial. The company faced regulatory scrutiny from CDSCO and reputational damage. The document was not stolen, it was accidentally discarded because it was not properly stored.
Supports Regulatory Compliance
Clear desk and clear screen policies are required or strongly recommended by multiple regulatory frameworks:
- ISO 27001: A.7.7 explicitly requires clear desk and clear screen policies
- PCI DSS: Requires protection of cardholder data from physical exposure, including clear desk practices
- HIPAA: Requires protection of PHI from unauthorized physical access, including workstation security
- RBI: Requires banks to protect customer data from physical exposure in branch and back-office environments
- SEBI: Requires market infrastructure institutions to protect sensitive market data from physical exposure
- GDPR: Requires protection of personal data from unauthorized access, including physical access
- DPDP Act 2023: Requires reasonable security safeguards for personal data, including physical protection
Auditors will always review clear desk and clear screen compliance during physical security assessments. A single unattended desk with a sensitive document can be a finding.
Reduces Social Engineering Risk
A cluttered desk provides information that can be used for social engineering attacks. An attacker who sees a document with a project name, a client name, or an internal phone number can use that information to craft a convincing phishing email or phone call. An attacker who sees a sticky note with a password or PIN has immediate access. An attacker who sees an org chart or contact list can identify targets for further attacks.
A Mumbai-based IT company with 300 employees experienced a spear-phishing attack that was highly successful because the attacker had obtained internal information from an employee's desk. The attacker, posing as a visitor, photographed a whiteboard with project names, team member names, and internal jargon. The subsequent phishing email used the exact project names and referenced team members by name, making it appear completely legitimate. 15 employees clicked the link, and the attacker gained access to the network. The clear desk policy would have prevented the initial information gathering.
Improves Workplace Safety and Professionalism
Beyond security, clear desk policies improve workplace safety and professionalism:
- Reduced clutter reduces fire hazards (paper is fuel)
- Reduced clutter improves emergency evacuation (clear pathways)
- Reduced clutter improves workplace hygiene and cleaning efficiency
- Clear screens reduce energy consumption (screen savers and sleep modes save power)
- A tidy workspace improves employee focus and productivity
- A professional appearance improves client and visitor impressions
A Noida-based BPO with 1,000 employees implemented a clear desk policy and reported that workplace cleanliness improved by 40%, employee productivity (measured by task completion rates) improved by 8%, and client audit scores improved significantly. The security benefits were accompanied by operational and cultural benefits.
Enables Rapid Incident Response
When a security incident occurs (e.g., a suspected insider threat, a visitor breach, or a loss of documents), a clear desk policy enables rapid incident response:
- The scope of potential exposure is limited to what was actually on the desk
- The investigation can quickly determine what was visible or accessible
- The organization can demonstrate that it had policies in place to prevent exposure
- Forensic investigators can quickly assess the physical scene without navigating clutter
Without a clear desk policy, incident response is hampered by the inability to determine what was exposed or stolen.
Scope and Applicability
Areas and Scenarios In Scope
Office Workspaces:
- Individual desks and cubicles
- Shared workstations and hot desks
- Open-plan office seating
- Manager and executive offices
- Reception and front desk areas
- Mail and package handling areas
- Break rooms and cafeterias (if employees work there)
- Training rooms and classrooms
- Library and reading areas
Meeting and Collaboration Spaces:
- Conference rooms and meeting rooms
- Huddle rooms and brainstorming spaces
- Video conferencing rooms
- Board rooms and executive meeting rooms
- Training rooms and auditoriums
- Interview rooms
- War rooms and project rooms
Common and Public Areas:
- Reception and waiting areas
- Lobby and visitor areas
- Printing and copying stations
- Fax and scanner stations
- Shared kiosks and terminals
- Library and resource centers
- Break rooms and cafeterias
- Gym and wellness centers (if work-related devices are used)
Remote and Mobile Work:
- Home offices and remote workspaces
- Co-working spaces and shared offices
- Coffee shops and public spaces where employees work
- Client sites and partner offices
- Hotels and airport lounges
- Vehicles and transport (if work is conducted in vehicles)
Specialized Environments:
- Data centers and server rooms
- Network operations centers (NOCs)
- Security operations centers (SOCs)
- Call centers and BPO floors
- Trading floors and dealing rooms
- Healthcare patient areas and clinical workstations
- Laboratory and research areas
- Manufacturing floor offices and control rooms
- Government and defense secure areas
Information and Assets In Scope
Papers and Documents:
- Printed reports, spreadsheets, and presentations
- Financial statements, invoices, and billing documents
- Contracts, agreements, and legal documents
- Customer lists, contact lists, and account information
- Employee records, payroll data, and HR documents
- Strategic plans, business cases, and board materials
- Research data, clinical trial data, and intellectual property
- Government filings, regulatory submissions, and audit reports
- Meeting minutes, notes, and whiteboard content
- Handwritten notes, sticky notes, and scratch paper
- Draft documents, redlined documents, and review copies
- Documents left on printers, copiers, and fax machines
- Documents in recycling bins and trash cans
- Documents on bulletin boards, whiteboards, and flip charts
Removable Storage Media:
- USB drives, flash drives, and thumb drives
- External hard drives and SSDs
- CDs, DVDs, and Blu-ray discs
- SD cards and memory cards
- Tape backups and backup cartridges
- Smartphones and tablets used for work
- Portable media players with work data
- Keys and access cards (if left on desks)
Information Processing Facilities:
- Desktop computers and workstations
- Laptop computers and docking stations
- Tablets and mobile devices
- Kiosks and public terminals
- Thin clients and virtual desktop terminals
- Point-of-sale (POS) terminals
- ATM terminals and banking kiosks
- Medical devices with screens (patient monitors, imaging systems)
- Industrial control systems with screens (SCADA, HMI)
- Smart boards and interactive displays
- Projectors and presentation screens
- Network management consoles and monitoring screens
Other Physical Items:
- Whiteboards with sensitive content
- Flip charts with meeting notes
- Sticky notes with passwords, PINs, or account numbers
- Business cards with sensitive contact information
- ID badges and access cards
- Keys and key cards for secure areas
- Printed photos of sensitive facilities or equipment
- Passwords and credentials written on paper
- Checklists and procedure documents with sensitive steps
- Internal phone directories and org charts
Organizational Size Considerations
Small Organizations (≤50 employees):
- Simple clear desk/clear screen policy (1–2 pages)
- Basic signage and reminders
- Manual screen lock (Windows key + L) training
- Simple locked storage (desk drawers, cabinets)
- Basic spot checks by manager or facilities
- Budget: –annually
Medium Organizations (50–500 employees):
- Formal clear desk/clear screen policy with enforcement procedures
- Signage, desk plates, and reminder stickers
- Automated screen lock (group policy, GPO, MDM)
- Locked storage (desk drawers, filing cabinets, storage cabinets)
- Regular spot checks and compliance monitoring
- Training program with annual refresher
- Budget: –annually
Large Organizations (≥500 employees):
- Complete clear desk/clear screen policy with detailed procedures
- Extensive signage, desk plates, and branded reminders
- Automated screen lock with centralized enforcement (GPO, Intune, MDM)
- Secure storage solutions (personal lockers, secure cabinets, smart storage)
- Regular audits, spot checks, and compliance monitoring
- Complete training program with testing and certification
- Integration with security awareness program and incident response
- Budget: –annually
Key Definitions
| Term | Definition |
|---|---|
| Clear Desk Policy | A policy requiring employees to remove all sensitive documents, removable media, and other information assets from their desk when it is unattended |
| Clear Screen Policy | A policy requiring employees to lock their computer screen or log out when their information processing facility is unattended |
| Unattended | A desk, workspace, or screen that is not actively monitored by the authorized user, includes lunch breaks, meetings, bathroom breaks, end-of-day, and any absence from the desk |
| Sensitive Information | Any information that is classified as Internal, Confidential, or Restricted, or that could be used to harm the organization if exposed |
| Removable Storage Media | Portable devices that store data and can be easily removed from the workplace (USB drives, external hard drives, CDs, SD cards) |
| Information Processing Facility | Any device used to process, store, or display information (computers, laptops, tablets, kiosks, terminals, monitors) |
| Visual Hacking | The unauthorized viewing of information by simply looking at documents, screens, or displays without technical tools |
| Screen Lock | A security feature that requires authentication (password, PIN, biometric) to unlock the screen and resume access |
| Screen Saver | A program that displays a moving image or blank screen after a period of inactivity; may or may not require authentication to exit |
| Automatic Screen Lock | A technical control that automatically locks the screen after a defined period of inactivity, requiring authentication to unlock |
| Locked Storage | A secure container (drawer, cabinet, locker, safe) that requires a key, combination, or access control to open |
| Personal Locker | A locker assigned to an individual employee for storing personal items and sensitive work materials |
| Secure Cabinet | A cabinet with a lock or access control used for storing sensitive documents and media |
| Hot Desk | A shared workstation used by multiple employees at different times, common in flexible work environments |
| Clean Desk | A desk that has no sensitive documents, media, or items visible when unattended |
| Desk Check | A physical inspection of desks and workspaces to verify compliance with the clear desk policy |
| Screen Check | A physical inspection of screens and terminals to verify compliance with the clear screen policy |
| Compliance Rate | The percentage of desks or screens that comply with the policy during an inspection |
| Violation | A failure to comply with the clear desk or clear screen policy, such as leaving a document on a desk or a screen unlocked when unattended |
| Escort | A person who accompanies a visitor or contractor and ensures they do not access unauthorized areas or information |
| Visitor Badge | A temporary identification badge worn by visitors to distinguish them from employees |
| Tailgating | The unauthorized entry of a person into a secure area by following an authorized person through a controlled access point |
| Shoulder Surfing | The unauthorized viewing of a screen or document by looking over someone's shoulder |
| Paper Shredder | A device that destroys paper documents by cutting them into small pieces, preventing reconstruction |
| Media Sanitizer | A device or process that securely destroys data on removable media (degausser, shredder, crusher) |
| Secure Disposal Bin | A locked container for collecting sensitive documents and media awaiting secure destruction |
| End-of-Day Procedure | A routine performed by employees at the end of each workday to secure their desk, screen, and workspace |
| Workspace Risk Assessment | An evaluation of the security risks associated with a specific workspace or desk location |
Relationship to Other Controls
Directly Related Controls
| Control | Relationship |
|---|---|
| A.5.10, Acceptable Use of Information | Clear desk/clear screen policies are part of acceptable use |
| A.5.12, Classification of Information | Classification determines what documents and media must be secured |
| A.5.13, Labeling of Information | Labels help employees identify what must be cleared |
| A.5.14, Information Transfer | Clear desk prevents unauthorized transfer of physical documents |
| A.5.16, Managing Changes | Changes to workspace layout may affect clear desk policy |
| A.5.20, Addressing Information Security Within Supplier Agreements | Contractor and vendor agreements must include clear desk requirements |
| A.5.36, Compliance with Policies, Rules and Standards for Information Processing | Clear desk/clear screen compliance is part of policy compliance |
| A.6.1, Screening | All personnel (including cleaning staff) must be screened |
| A.6.2, Terms and Conditions of Employment | Employment terms must include clear desk/clear screen obligations |
| A.6.3, Information Security Awareness Training | Training must cover clear desk/clear screen policies |
| A.7.1, Physical Security Perimeters | Physical perimeters protect areas where clear desk/clear screen applies |
| A.7.2, Physical Entry Controls | Entry controls limit who can access areas where desks and screens are located |
| A.7.3, Securing Offices, Rooms and Facilities | Office security supports clear desk/clear screen policies |
| A.7.4, Physical Security Monitoring | Monitoring (CCTV) detects violations of clear desk/clear screen policies |
| A.7.5, Protecting Against Physical and Environmental Threats | Environmental threats (fire, flood) are mitigated by clear desks |
| A.7.6, Equipment Maintenance | Maintenance of printers and copiers prevents document accumulation |
| A.7.7, Clear Desk and Clear Screen | This is the core control |
| A.7.8, Equipment Siting and Protection | Equipment siting affects screen visibility and desk security |
| A.7.9, Storage Media | Storage media must be cleared from desks and secured |
| A.7.10, Disposal of Media | Media disposal is part of the clear desk policy |
| A.8.1, User Endpoint Devices | Endpoint devices must have clear screen policies and screen locks |
| A.8.5, Secure Authentication | Authentication (passwords, biometrics) is used for screen locks |
| A.8.7, Protection Against Malware | Screen locks prevent unauthorized malware installation |
| A.8.10, Information Deletion | Deleted documents and media must be securely disposed of |
| A.8.15, Logging | Screen lock and unlock events may be logged |
| A.8.16, Monitoring Activities | Monitoring detects clear desk/clear screen violations |
| A.8.20, Networks Security | Network security is complemented by physical screen security |
| A.8.23, Web Filtering | Web filtering prevents unauthorized browsing on unlocked screens |
Indirectly Related Controls
| Control | Relationship |
|---|---|
| A.5.8, Information and Other Assets | Asset inventory identifies what must be protected by clear desk/clear screen |
| A.5.9, Inventory of Information and Other Assets | Inventory tracks assets that may be left on desks |
| A.5.11, Return of Assets | Returned assets must be cleared from desks |
| A.5.18, Information Security in ICT Supply Chain | Supply chain security includes clear desk requirements for contractors |
| A.5.21, Managing Information Security in ICT | Cloud security is complemented by physical screen security |
| A.5.24, Information Security Incident Management | Clear desk violations may trigger incident response |
| A.5.25, Assessment and Decision on Information Security Risks | Risk assessment includes visual hacking and physical exposure risks |
| A.5.29, Information Security During Disruption | Clear desk policies apply during disruptions (e.g., evacuations) |
| A.5.31, Legal, Statutory, Regulatory and Contractual Requirements | Legal requirements may mandate clear desk practices |
| A.5.34, Privacy and Protection of PII | Clear desk protects PII from physical exposure |
| A.7.11, Physical Media Transfer | Clear desk prevents unauthorized media transfer |
| A.7.12, Equipment Maintenance | Maintenance of secure storage (cabinets, lockers) is part of the program |
| A.7.13, Equipment Maintenance | Maintenance of physical security equipment supports clear desk |
| A.7.14, Equipment Maintenance | Maintenance ensures secure storage remains functional |
Implementation Roadmap
Figure · Matrix
Comparison: Weekly to Event-triggered
Phase 1: Policy Design (Weeks 1–2)
| Week | Activity | Deliverable |
|---|---|---|
| 1 | Assess workspace risks and current compliance | Workspace risk assessment |
| 2 | Design clear desk and clear screen policy | Policy document |
Phase 2: Technical and Physical Controls (Weeks 3–4)
| Week | Activity | Deliverable |
|---|---|---|
| 3 | Deploy automated screen lock (GPO, MDM, Intune) | Screen lock deployed |
| 4 | Deploy secure storage (drawers, cabinets, lockers) | Secure storage deployed |
Phase 3: Communication and Training (Weeks 5–6)
| Week | Activity | Deliverable |
|---|---|---|
| 5 | Install signage, desk plates, and reminders | Signage deployed |
| 6 | Train all employees on policy and procedures | Training completion records |
Phase 4: Enforcement and Monitoring (Weeks 7–8)
| Week | Activity | Deliverable |
|---|---|---|
| 7 | Begin spot checks and compliance monitoring | Compliance monitoring reports |
| 8 | Implement violation handling and remediation | Violation records and remediation |
Phase 5: Continuous Improvement (Ongoing)
| Frequency | Activity | Deliverable |
|---|---|---|
| Weekly | Informal spot checks by managers and security | Spot check notes |
| Monthly | Formal compliance audits by security team | Monthly compliance report |
| Quarterly | Policy review and refinement | Quarterly review report |
| Bi-annually | Refresher training | Training records |
| Annually | Complete policy review and risk assessment | Annual review report |
| Event-triggered | Incident-driven reviews and updates | Incident review report |
Detailed Guidance
Clear Desk Policy Elements
Policy Statement:
"All employees must maintain a clear desk when their workspace is unattended. No sensitive documents, removable storage media, or other information assets may be left visible on desks, in printers, or in open areas when the employee is not present. All sensitive items must be secured in locked storage."
Key Requirements:
- No sensitive documents on desks when unattended, All documents containing Internal, Confidential, or Restricted information must be removed from the desk surface when the employee leaves, even for short periods (lunch, meetings, breaks)
- No removable storage media on desks, USB drives, external hard drives, CDs, SD cards, and other storage media must not be left on desks when unattended
- No passwords or credentials on desks, Passwords, PINs, access codes, and other credentials must not be written on paper, sticky notes, or whiteboards on or near the desk
- No sensitive items in open drawers, Desk drawers that are not lockable must be cleared of sensitive items when unattended
- No sensitive items in trash or recycling, Sensitive documents must be shredded, not placed in regular trash or recycling bins
- No sensitive items on printers, copiers, or fax machines, Documents must be collected immediately from printers, copiers, and fax machines; uncollected documents must be removed by facilities and placed in secure disposal
- No sensitive items on whiteboards or flip charts, Whiteboards and flip charts must be erased after meetings; sensitive content must not be left visible
- No sensitive items on bulletin boards, Bulletin boards must not display sensitive information (e.g., org charts with names, contact lists, project details)
- End-of-day clearance, At the end of each workday, employees must completely clear their desk of all sensitive items and secure them in locked storage
- Visitor presence, When visitors are present in the office, employees must be especially vigilant about clear desk compliance
Exceptions:
- Documents that are actively being worked on and are within arm's reach of the employee while they are present at the desk (but must be cleared when the employee leaves)
- Public documents (marked PUBLIC) that are intended for general distribution
- Personal items that do not contain sensitive information (but should be minimized)
- Items in locked storage (locked drawers, cabinets, lockers) that are not visible
Clear Screen Policy Elements
Policy Statement:
"All employees must lock their computer screen or log out whenever their information processing facility is unattended. Screen locks must be activated automatically after a defined period of inactivity. Screens must not display sensitive information when unattended."
Key Requirements:
- Manual screen lock, Employees must manually lock their screen (Windows key + L, Ctrl+Alt+Del + Lock, or equivalent) whenever they leave their workstation, even for short periods
- Automatic screen lock, Screens must lock automatically after a defined period of inactivity (e.g., 5 minutes for desktops, 2 minutes for laptops, 1 minute for shared/public terminals)
- Password-protected screen lock, Screen locks must require authentication (password, PIN, or biometric) to unlock; simple screen savers without password protection are not acceptable
- No sensitive information on unlocked screens, Employees must not leave sensitive documents or applications open on the screen when they leave; they must close, minimize, or lock the screen
- Shared and public terminals, Shared workstations, kiosks, and public terminals must log out after each session and require authentication for the next session
- Mobile devices, Mobile devices (smartphones, tablets) must lock automatically and require authentication (PIN, biometric, or password) to unlock
- Presentation screens, Screens used for presentations must not display sensitive information when the presenter is not present; they must be locked or turned off
- Remote desktop sessions, Remote desktop sessions must lock when unattended and must not be left open on shared or public terminals
- Multi-monitor setups, All monitors in a multi-monitor setup must lock when the screen is locked; the lock must cover all displays
- Projectors and shared displays, Projectors and shared displays must be turned off or disconnected when not in use for presentations; they must not display sensitive information
Exceptions:
- Screens in secure areas with no visitor access and constant employee presence (e.g., SOC, NOC) may have longer inactivity timers, but must still lock when the area is unattended
- Screens used for public displays (reception, lobby) that display only public information may not require locking, but must be physically secured
- Screens in dedicated, locked, single-user offices may have relaxed requirements if the office is locked when the user is absent
Technical Controls for Screen Lock Enforcement
Windows Group Policy (GPO):
- Enable screen saver: Enabled
- Screen saver timeout: 300 seconds (5 minutes) for desktops, 120 seconds (2 minutes) for laptops
- Password protect the screen saver: Enabled
- Require password on wake: Enabled
- Prevent changing screen saver: Enabled (to prevent users from disabling it)
- Prevent changing lock screen image: Enabled (to enforce branding and security message)
- Interactive logon: Machine inactivity limit: 300 seconds (5 minutes)
Microsoft Intune / MDM:
- Device lock: Enabled
- Inactivity timeout: 5 minutes for desktops, 2 minutes for mobile devices
- Password required to unlock: Enabled
- Minimum password length: 6+ characters
- Biometric authentication: Allowed (if supported)
- Prevent users from changing lock settings: Enabled
macOS Configuration:
- Require password after sleep or screen saver begins: Immediately
- Start screen saver after: 5 minutes of inactivity
- Show a message when the screen is locked: "This screen is locked. Unauthorized access is prohibited."
- Disable automatic login: Enabled
Linux (GNOME/KDE):
- Screen lock: Enabled
- Lock screen after: 5 minutes of inactivity
- Require password to unlock: Enabled
- Blank screen after: 5 minutes of inactivity
- Lock screen when screensaver activates: Enabled
Mobile Devices (iOS/Android via MDM):
- Passcode required: Enabled
- Auto-lock: 1 minute (iOS) or 2 minutes (Android)
- Require passcode on device wake: Enabled
- Biometric authentication: Allowed
- Erase data after failed attempts: 10 attempts (for devices with sensitive data)
Kiosks and Public Terminals:
- Session timeout: 5 minutes of inactivity
- Log out after session timeout: Enabled
- Clear browser cache and history after session: Enabled
- Require authentication for each session: Enabled
- Disable USB ports (if not needed): Enabled
- Restricted shell or kiosk mode: Enabled
Physical Controls for Clear Desk Enforcement
Secure Storage Solutions:
- Lockable desk drawers: All desks must have at least one lockable drawer for storing sensitive documents. Keys must be kept with the employee or in a secure key management system.
- Filing cabinets: Shared filing cabinets must be locked when not in use. Cabinets containing sensitive information must be in areas with access controls.
- Personal lockers: In open-plan offices or hot-desking environments, personal lockers must be provided for each employee to store sensitive materials overnight.
- Secure storage cabinets: Cabinets with combination locks or access control for storing sensitive documents, media, and equipment.
- Safes: For highly sensitive materials (RESTRICTED documents, backup tapes, cryptographic keys), safes with combination or biometric locks must be provided.
- Cable locks: For laptops and mobile devices, cable locks (Kensington locks) must be provided to secure devices to desks when unattended.
- Media safes: Fireproof and waterproof safes for storing backup media and critical documents.
Signage and Reminders:
- Desk plates: Small signs or plates on each desk stating "Clear Desk Policy, Please Secure All Sensitive Documents"
- Wall signage: Posters in office areas, meeting rooms, and near printers reminding employees of the clear desk and clear screen policies
- Screen stickers: Small stickers on monitors or laptop screens reminding employees to lock their screen when leaving
- Keyboard stickers: Stickers on keyboards with the screen lock shortcut (e.g., "Windows + L = Lock Screen")
- Floor decals: Decals near exits or common areas reminding employees to clear their desk before leaving
- Digital reminders: Screensavers or desktop wallpapers with security messages reminding employees of the policies
- Email reminders: Periodic email reminders from the CISO or security team about clear desk/clear screen compliance
- Screensaver messages: Messages on screensavers reminding employees of the policy (e.g., "This screen is locked. Unauthorized access is prohibited. Contact security@company.com for access.")
Printer and Copier Controls:
- Secure print release: Employees must authenticate at the printer to release their print jobs (prevents uncollected documents from sitting in output trays)
- Automatic deletion: Print jobs that are not released within a defined time (e.g., 15 minutes) are automatically deleted
- Printer location: Printers for sensitive documents must be located in areas with access controls, not in public or visitor areas
- Printer monitoring: Printers and copiers must be monitored for uncollected documents; facilities staff must clear and secure uncollected documents
- Document collection policy: Employees must collect documents immediately after printing; documents left at printers for more than 15 minutes are considered a violation
Whiteboard and Flip Chart Controls:
- Whiteboard erasers: Erasers must be readily available at every whiteboard
- "Erase after use" signs: Signs on whiteboards and flip charts reminding users to erase or remove sensitive content after meetings
- Whiteboard covers: Covers or shutters for whiteboards in public areas to prevent visual exposure when not in use
- Flip chart removal: Flip chart pages with sensitive content must be removed and stored securely or shredded after meetings
- Digital whiteboards: Digital whiteboards must be configured to clear content after meetings and require authentication to access saved content
Visitor and Contractor Controls:
- Visitor escorts: Visitors must be escorted at all times in areas with desks and screens; escorts must ensure visitors do not view or photograph sensitive information
- Visitor badges: Visitors must wear conspicuous badges to identify them as non-employees
- Visitor areas: Visitors must be received in designated visitor areas, not in work areas with sensitive information
- Contractor agreements: Contractors must sign agreements acknowledging the clear desk/clear screen policy and agreeing to comply
- Contractor training: Contractors must receive basic security awareness training, including clear desk/clear screen requirements, before starting work
- Cleaning staff controls: Cleaning staff must be screened, trained, and supervised. They must not access locked drawers or cabinets. Cleaning must be scheduled during work hours when employees are present, or after hours with security supervision.
End-of-Day Procedure
Every employee must perform the following end-of-day procedure:
- Lock screen: Lock the computer screen or log out (Windows + L or equivalent)
- Close applications: Close all applications containing sensitive information (or ensure the screen is locked)
- Clear desk: Remove all sensitive documents from the desk surface and place them in locked storage
- Secure media: Remove all USB drives, external drives, CDs, and other media from the desk and place them in locked storage
- Secure credentials: Remove any sticky notes or papers with passwords, PINs, or access codes from the desk and shred them
- Clear whiteboard: Erase any sensitive content from whiteboards or flip charts near the desk
- Collect prints: Collect any documents from the printer, copier, or fax machine
- Shred or secure: Shred any sensitive documents that are no longer needed; secure those that are needed in locked storage
- Lock drawers: Lock all desk drawers containing sensitive items
- Secure devices: If the office is not locked, secure laptops and mobile devices with cable locks or place them in locked storage
- Verify: Do a final visual check of the desk to ensure nothing sensitive is visible
- Report issues: Report any security concerns (e.g., broken locks, missing storage, suspicious activity) to security or facilities
For employees who work remotely, an adapted end-of-day procedure must be followed:
- Lock the computer screen or shut down the device
- Secure all sensitive documents in a locked drawer or cabinet
- Secure all removable media in a locked drawer or cabinet
- Ensure the home office is not visible to visitors or family members who should not see sensitive information
- If working in a shared space (co-working, coffee shop), ensure all materials are collected and secured before leaving
Compliance Monitoring and Enforcement
Spot Checks:
- Informal spot checks by managers, team leads, and security personnel during office hours
- Check for unlocked screens, visible documents, and unsecured media
- Spot checks should be random and unannounced to ensure genuine compliance
- Results should be documented and feedback provided to employees
- Spot checks should be positive and educational, not punitive (unless repeated violations occur)
Formal Audits:
- Monthly or quarterly formal audits by the security team or facilities team
- Audits cover all work areas, meeting rooms, and common areas
- Audit checklist includes: screen lock status, desk surface, open drawers, printers, whiteboards, and shared spaces
- Audit results are documented in a compliance report
- Audit results are shared with management and aggregated for trend analysis
- Areas with poor compliance are targeted for additional training and enforcement
Self-Assessment:
- Employees are encouraged to self-assess their workspace at the end of each day
- Self-assessment checklist posted at workstations or in the employee handbook
- Self-assessment creates a culture of personal responsibility rather than external enforcement
Peer Awareness:
- Employees are encouraged to remind colleagues to lock their screens or clear their desks
- A "security buddy" system where colleagues check each other's workspaces at the end of the day
- Positive peer pressure is more effective than top-down enforcement for behavioral change
Violation Handling:
- First violation: Verbal reminder and education from the employee's manager or security team
- Second violation: Written warning and mandatory refresher training
- Third violation: Formal disciplinary action (e.g., note in personnel file, performance review impact)
- Repeated violations: Escalation to HR and potential termination if the employee is willfully negligent
- Intentional violations: Immediate disciplinary action, including potential termination and legal action if the violation involves theft or espionage
- Visitor/contractor violations: Removal of the visitor/contractor from the premises and review of their access privileges
Positive Reinforcement:
- Recognition and rewards for departments or teams with high compliance rates
- Security awareness contests or challenges with prizes for clear desk/clear screen compliance
- Public recognition of employees who demonstrate good security habits
- Integration into performance reviews and appraisals for roles with high security sensitivity
Tools and Technologies
Screen Lock Enforcement Tools
| Tool | Type | Key Features | licensing Range |
|---|---|---|---|
| Microsoft Group Policy (GPO) | Windows | Screen lock, timeout, password protection, prevents user changes | Free (included in Windows) |
| Microsoft Intune | Cloud MDM | Screen lock, timeout, password policy, biometric, mobile device management | Included in Microsoft 365 E3/E5 |
| Idle Screen Lock | Open-source | Idle detection, automatic lock, timeout configuration | Free |
| xPrintIdle | Linux | Idle detection, automatic lock for Linux | Free |
Secure Storage Solutions
| Solution | Type | Key Features | licensing Range |
|---|---|---|---|
| Lockable Desk Drawers | Furniture | Standard desk with lockable drawer; key or combination | |
| Filing Cabinets | Furniture | Metal filing cabinet with lock; 2-drawer, 4-drawer, lateral | |
| Personal Lockers | Furniture | Individual locker for employee use; key or combination | |
| Storage Cabinets | Furniture | Secure cabinet with lock for media and documents; fireproof options | |
| Safes | Security | Combination or biometric safe for highly sensitive materials; fireproof/waterproof | |
| Media Safes | Security | Fireproof safe for backup tapes and media; specialized for media protection | |
| Key Cabinets | Security | Electronic key cabinet with access logging and audit trail | |
| Cable Locks (Kensington) | Device Security | Laptop cable lock; combination or key lock | |
| Desk Mount Laptop Locks | Device Security | Mounting bracket with lock for laptop storage | |
| Smart Lockers | Smart Storage | Electronic locker with card or biometric access; audit logging | |
| Document Shredders | Disposal | Cross-cut shredder for sensitive documents; personal and office sizes | |
| Media Degaussers | Disposal | Degaussing machine for destroying magnetic media data | |
| Media Shredders | Disposal | Shredder for CDs, DVDs, hard drives, and other media | |
| Secure Disposal Bins | Disposal | Locked bin for collecting sensitive documents awaiting shredding |
Signage and Reminder Tools
| Tool | Type | Key Features | licensing Range |
|---|---|---|---|
| Desk Plates | Signage | Acrylic or metal desk plate with clear desk policy reminder | |
| Wall Posters | Signage | Laminated posters with clear desk/clear screen policy and tips | |
| Screen Stickers | Signage | Small sticker for monitors with screen lock shortcut reminder | |
| Keyboard Stickers | Signage | Sticker for keyboard with lock shortcut (e.g., "Windows + L") | |
| Floor Decals | Signage | Removable floor decals near exits reminding employees to clear desks | |
| Digital Signage | Signage | Screens in common areas rotating security reminders and tips | |
| Screensaver Messages | Software | Custom screensaver with security message and company branding | Free (custom design) |
| Desktop Wallpapers | Software | Custom desktop wallpaper with security reminders and lock shortcut | Free (custom design) |
| Email Reminder Templates | Communication | Pre-designed email templates for periodic security reminders | Free (custom design) |
Monitoring and Audit Tools
| Tool | Type | Key Features |
|---|---|---|
| CCTV Systems | Physical Monitoring | Camera monitoring of work areas to detect clear desk violations; evidence collection |
| Security Patrols | Physical Monitoring | Regular security patrols of office areas to check for unlocked screens and visible documents |
| Compliance Audit Checklists | Audit | Standardized checklists for formal clear desk/clear screen audits |
| Mobile Audit Apps | Audit | Tablet or smartphone apps for conducting and documenting spot checks and audits |
| Screen Lock Monitoring | Technical | Tools that monitor and report screen lock status across the network (via event logs) |
| Printer Management Software | Technical | Tools that monitor print queues, secure print release, and uncollected document tracking |
| Access Control Logs | Technical | Logs that track who entered secure areas and when, supporting incident investigation |
| Visitor Management Systems | Technical | Systems that track visitor presence, escort status, and area access |
| Security Information and Event Management (SIEM) | Technical | Integration of screen lock events, access logs, and physical security events for correlation |
Policy Templates and Documentation
Clear Desk and Clear Screen Policy (Template)
Template
Clear Desk and Clear Screen Policy
1. Purpose
This policy establishes the requirements for maintaining clear desks and clear screens to protect sensitive information from unauthorized physical access, visual exposure, and theft.
2. Scope
Applies to all employees, contractors, temporary staff, vendors, and visitors who access the organization's workspaces, offices, meeting rooms, and remote work locations. Applies to all desks, workstations, screens, printers, meeting rooms, and shared spaces.
3. Policy Statements
3.1 Clear Desk Requirements
- All employees must maintain a clear desk when their workspace is unattended
- Sensitive documents (Internal, Confidential, or Restricted) must not be left visible on desks, chairs, or nearby surfaces when unattended
- Removable storage media (USB drives, external hard drives, CDs, SD cards) must not be left on desks when unattended
- Passwords, PINs, access codes, and credentials must not be written on paper, sticky notes, or whiteboards on or near desks
- Documents must be collected immediately from printers, copiers, and fax machines
- Sensitive documents must not be placed in regular trash or recycling bins; they must be shredded
- Whiteboards and flip charts must be erased after meetings; sensitive content must not be left visible
- At the end of each workday, all sensitive items must be removed from the desk and secured in locked storage
3.2 Clear Screen Requirements
- All employees must lock their computer screen or log out whenever their workstation is unattended
- Screens must lock automatically after 5 minutes of inactivity for desktops and 2 minutes for laptops and mobile devices
- Screen locks must require authentication (password, PIN, or biometric) to unlock
- Employees must not leave sensitive applications or documents visible on unlocked screens when unattended
- Shared workstations and public terminals must log out after each session and require authentication for the next session
- Projectors and shared displays must be turned off or disconnected when not in use for presentations
- All monitors in a multi-monitor setup must lock when the screen is locked
3.3 Secure Storage Requirements
- All employees must have access to lockable storage for sensitive documents and media (lockable desk drawer, filing cabinet, or personal locker)
- Lockable storage must be used whenever the employee is not present at their desk
- Shared filing cabinets containing sensitive information must be locked when not in use
- Highly sensitive materials (RESTRICTED documents, backup media, cryptographic keys) must be stored in a safe or secure cabinet
- Laptops and mobile devices must be secured with cable locks or placed in locked storage when unattended in unlocked offices
3.4 Printer and Copier Requirements
- Sensitive documents must be printed only when the employee is present to collect them
- Secure print release must be used for sensitive documents (authentication at the printer to release the job)
- Print jobs not collected within 15 minutes must be deleted or secured by facilities
- Printers and copiers in public or visitor areas must not be used for sensitive documents
- Documents left at printers, copiers, or fax machines are considered a clear desk violation
3.5 Meeting Room Requirements
- Whiteboards and flip charts must be erased after meetings; sensitive content must not be left visible
- Meeting rooms must be checked for left-behind documents, media, and devices after each meeting
- Laptops and devices left in meeting rooms must be locked and secured
- Visitors in meeting rooms must not be left unattended with access to sensitive materials
3.6 Visitor and Contractor Requirements
- Visitors must be escorted at all times in work areas and must not be left unattended near desks or screens
- Contractors must comply with the clear desk/clear screen policy as a condition of their contract
- Cleaning staff must be trained and supervised; they must not access locked storage or handle sensitive documents
- Visitors and contractors who violate the policy may be removed from the premises and have their access revoked
3.7 Remote Work Requirements
- Remote workers must secure sensitive documents and media in locked storage at their home office when not in use
- Remote workers must lock their screen whenever they leave their workstation
- Remote workers working in shared spaces (co-working, coffee shops) must ensure all materials are collected and secured before leaving
- Remote workers must ensure that family members, visitors, or others cannot view sensitive information on screens or documents
3.8 End-of-Day Procedure
All employees must perform the following end-of-day procedure:
- Lock the computer screen or log out
- Close or secure all sensitive applications
- Remove all sensitive documents from the desk and place them in locked storage
- Remove all removable media from the desk and place them in locked storage
- Remove any written passwords or credentials from the desk and shred them
- Erase any sensitive content from whiteboards or flip charts
- Collect all documents from printers and copiers
- Shred unneeded sensitive documents; secure needed documents in locked storage
- Lock all desk drawers containing sensitive items
- Secure laptops and devices with cable locks or in locked storage
- Perform a final visual check to ensure nothing sensitive is visible
3.9 Compliance Monitoring
- Informal spot checks will be conducted by managers, security, and facilities
- Formal audits will be conducted monthly/quarterly by the security team
- Compliance rates will be tracked and reported to management
- Violations will be documented and addressed through the violation handling procedure
3.10 Violation Handling
- First violation: Verbal reminder and education
- Second violation: Written warning and mandatory refresher training
- Third violation: Formal disciplinary action
- Repeated violations: Escalation to HR and potential termination
- Intentional violations: Immediate disciplinary action, including potential termination and legal action
4. Roles and Responsibilities
- All Employees: Comply with the clear desk and clear screen policy; perform the end-of-day procedure; report security concerns
- Managers: Monitor and enforce compliance within their teams; conduct spot checks; address violations
- Security Team: Conduct formal audits; track compliance metrics; investigate violations; provide training
- Facilities Team: Manage secure storage, printers, and disposal; supervise cleaning staff; support audits
- IT Team: Configure and enforce automatic screen lock policies; provide technical support for secure storage
- HR: Include policy compliance in onboarding and performance reviews; handle disciplinary actions
- Visitors and Contractors: Comply with the policy while on premises; follow escort requirements
5. Exceptions
- Documents actively being worked on and within arm's reach while the employee is present at the desk (must be cleared when the employee leaves)
- Public documents marked PUBLIC and intended for general distribution
- Items in locked storage that are not visible
- Screens in secure areas with no visitor access and constant employee presence (relaxed timer requirements, but must still lock when unattended)
6. Review
This policy is reviewed annually and updated as needed.
Approved by: _______________ Date: _______________ CISO / Facilities Manager / HR Director
Supporting Document Templates
End-of-Day Checklist:
Template
End-of-Day Security Checklist
Employee Name: _______________ Date: _______________ Department: _______________ Workspace Location: _______________
Screen Security:
- Computer screen is locked or logged out
- All sensitive applications are closed or secured
- Laptop is secured (cable lock or locked storage)
Desk Security:
- No sensitive documents visible on desk surface
- No removable media (USB, CD, external drive) on desk
- No passwords or credentials written on paper or sticky notes
- All sensitive documents are in locked storage
- All removable media are in locked storage
- Desk drawers containing sensitive items are locked
Printer and Copier:
- All printed documents have been collected
- No documents left in printer output tray
- No documents left in copier or scanner
Whiteboard and Flip Chart:
- Whiteboard is erased (if sensitive content was written)
- Flip chart pages with sensitive content are removed and secured or shredded
Trash and Recycling:
- No sensitive documents in regular trash or recycling
- Sensitive documents are in secure disposal bin or shredded
Final Check:
- Visual check confirms nothing sensitive is visible
- Workspace is ready for overnight security
Signature: _______________ Time: _______________
Risk Assessment
Risks of Inadequate Clear Desk and Clear Screen Policies
| Risk | Likelihood | Impact | Risk Score | Mitigation |
|---|---|---|---|---|
| Visual hacking of sensitive documents | Very High | Medium | High | Implement clear desk policy with secure storage |
| Visual hacking of sensitive screen content | Very High | Medium | High | Implement clear screen policy with automatic screen lock |
| Theft of documents from unattended desks | High | High | Critical | Implement clear desk policy and locked storage |
| Theft of removable media from desks | High | High | Critical | Implement clear desk policy and locked storage |
| Social engineering from desk information | Medium | High | High | Implement clear desk policy and visitor controls |
| Accidental data loss or disposal | Medium | Medium | Medium | Implement clear desk policy and secure disposal |
| Unauthorized access to unlocked screens | High | High | Critical | Implement clear screen policy with automatic lock |
| Shoulder surfing in open-plan offices | High | Medium | High | Implement screen privacy filters and clear screen policy |
| Data exposure during meetings | Medium | High | High | Implement meeting room controls and clear desk policy |
| Visitor access to sensitive information | Medium | High | High | Implement visitor escort and clear desk policy |
| Cleaning staff exposure to documents | Medium | Medium | Medium | Implement clear desk policy and cleaning staff training |
| Remote work exposure to family/visitors | Medium | Medium | Medium | Implement remote work clear desk policy |
Risk Treatment Plan
| Risk | Treatment | Owner | Timeline |
|---|---|---|---|
| Visual hacking of documents | Deploy clear desk policy, secure storage, and signage | Security Manager | 2 weeks |
| Visual hacking of screens | Deploy automatic screen lock and clear screen policy | IT | 1 week |
| Theft of documents and media | Deploy locked storage and clear desk policy | Facilities | 2 weeks |
| Unauthorized screen access | Deploy automatic screen lock with password protection | IT | 1 week |
| Social engineering | Deploy clear desk policy and visitor controls | Security Manager | 2 weeks |
| Shoulder surfing | Deploy screen privacy filters and clear screen policy | IT / Facilities | 2 weeks |
| Meeting room exposure | Deploy meeting room controls and post-meeting checks | Facilities | 2 weeks |
| Visitor access | Deploy visitor escort and reception controls | Security Manager | 2 weeks |
Audit and Assessment Checklist
Documentation Review
- Is there a documented Clear Desk and Clear Screen Policy?
- Is the policy communicated to all employees, contractors, and visitors?
- Is there an end-of-day procedure documented?
- Are there secure storage solutions available for all employees?
- Is there signage and reminders in work areas?
- Is there training material on clear desk/clear screen?
- Is there a compliance monitoring and audit procedure?
- Is there a violation handling procedure?
- Are there exceptions documented and approved?
- Is the policy reviewed annually?
Implementation Review
- Are screens configured to lock automatically after a defined period of inactivity?
- Do screen locks require authentication (password, PIN, biometric)?
- Are all employees trained on the clear desk and clear screen policy?
- Is there evidence of secure storage (lockable drawers, cabinets, lockers) for all employees?
- Is there signage and reminders visible in work areas?
- Are printers configured for secure print release or monitored for uncollected documents?
- Are whiteboards and flip charts erased after meetings?
- Are visitors escorted in work areas?
- Are cleaning staff trained and supervised?
- Is there evidence of spot checks or compliance audits?
- Are remote workers trained on clear desk/clear screen for home offices?
Effectiveness Review
- What is the compliance rate during spot checks? (Target: ≥95%)
- What is the screen lock compliance rate? (Target: ≥99%)
- How many clear desk violations were detected in the last quarter? (Target: decreasing trend)
- How many clear screen violations were detected in the last quarter? (Target: decreasing trend)
- Are there any recurring violation patterns or areas?
- Is the training effective based on compliance rates?
- Are employees aware of the policy and why it matters?
- Is the policy still appropriate for the current work environment (remote, hybrid, open plan)?
- Are there any physical layout changes that affect the policy?
- Are there any new technologies or work practices that affect the policy?
Metrics and KPIs
Figure · Measures
The measures that show A.7.7 is working
- Clear Desk Compliance Rate≥95%Monthly
- Clear Screen Compliance Rate≥99%Monthly
- End-of-Day Compliance Rate≥95%Monthly
- Meeting Room Clearance Rate≥95%Weekly
- Printer Collection Rate≥95%Weekly
Compliance Metrics
| KPI | Formula | Target | Frequency |
|---|---|---|---|
| Clear Desk Compliance Rate | % of desks compliant during spot checks | ≥95% | Monthly |
| Clear Screen Compliance Rate | % of screens locked during spot checks | ≥99% | Monthly |
| End-of-Day Compliance Rate | % of employees performing end-of-day procedure | ≥95% | Monthly |
| Meeting Room Clearance Rate | % of meeting rooms cleared after meetings | ≥95% | Weekly |
| Printer Collection Rate | % of print jobs collected within 15 minutes | ≥95% | Weekly |
| Whiteboard Erasure Rate | % of whiteboards erased after meetings | ≥95% | Weekly |
| Violation Rate | Number of violations per month | Decreasing trend | Monthly |
| Repeat Violation Rate | % of violations that are repeat offenses | ≤10% | Monthly |
| Training Completion Rate | % of employees completing clear desk/screen training | ≥95% | Quarterly |
| Training Test Score | Average score on clear desk/screen knowledge test | ≥90% | Quarterly |
Operational Metrics
| KPI | Formula | Target | Frequency |
|---|---|---|---|
| Screen Lock Timeout Compliance | % of devices with correct screen lock timeout | 100% | Monthly |
| Secure Storage Availability | % of employees with access to lockable storage | 100% | Quarterly |
| Signage Coverage | % of work areas with clear desk/screen signage | 100% | Quarterly |
| Secure Print Usage | % of sensitive print jobs using secure print release | ≥90% | Monthly |
| Shredder Usage | % of sensitive documents shredded vs. discarded | ≥95% | Monthly |
| Visitor Escort Compliance | % of visitors escorted in work areas | 100% | Weekly |
| Cleaning Staff Training | % of cleaning staff trained on clear desk policy | 100% | Quarterly |
| Remote Work Compliance | % of remote workers compliant with clear desk/screen | ≥90% | Quarterly |
| Policy Exception Rate | Number of approved exceptions | Minimal | Quarterly |
| Policy Review Timeliness | Policy reviewed within annual cycle | 100% | Annual |
Business Impact Metrics
| KPI | Formula | Target | Frequency |
|---|---|---|---|
| Visual Hacking Incidents | Number of visual hacking incidents detected | 0 | Monthly |
| Document Theft Incidents | Number of document theft incidents | 0 | Monthly |
| Media Theft Incidents | Number of removable media theft incidents | 0 | Monthly |
| Social Engineering Incidents | Number of social engineering incidents using desk information | 0 | Monthly |
| Accidental Data Loss | Number of accidental data loss incidents from desks | 0 | Monthly |
| Visitor-Related Incidents | Number of incidents involving visitor access to desk information | 0 | Monthly |
| Audit Findings | Number of clear desk/screen-related audit findings | 0 | Annual |
| Regulatory Findings | Number of regulatory findings related to clear desk/screen | 0 | Annual |
| Employee Productivity | Measure of employee productivity (if tracked) | Stable or improving | Annual |
| Workplace Satisfaction | Employee satisfaction with workspace security | ≥80% | Annual |
Common Pitfalls and How to Avoid Them
Policy Is Written but Not Enforced
Pitfall: The organization has a clear desk/clear screen policy on paper, but it is never enforced. Employees ignore it, and management does not address violations. Impact: The policy becomes a "paper exercise" with no real effect. Compliance is low, and the organization has a false sense of security. Auditors will identify this as a finding. Solution: Enforcement requires a combination of technical controls (automatic screen lock), physical controls (secure storage), training, monitoring, and consequences. Managers must be held accountable for compliance in their teams. Violations must be addressed consistently, even if they seem minor. Start with positive reinforcement and education, but escalate to disciplinary action for repeated violations. Make compliance visible, publish compliance rates by department and recognize high performers.
No Secure Storage Available
Pitfall: The organization requires employees to clear their desks but does not provide lockable storage (drawers, cabinets, lockers). Employees have nowhere to put sensitive documents and media. Impact: Employees leave documents in unlocked drawers, under keyboards, or in bags under desks. The policy is unenforceable because the infrastructure does not support it. Solution: Provide lockable storage for every employee. At minimum, every desk should have a lockable drawer. In open-plan or hot-desking environments, provide personal lockers. For shared workspaces, provide secure cabinets. The impact of lockable storage is minimal compared to the impact of a data breach. Do not implement the policy before providing the infrastructure to support it.
Screen Lock Timeout Is Too Long or Not Enforced
Pitfall: Screens are set to lock after 30 minutes or longer, or the screen lock is not enforced by group policy and users can disable it. Impact: Screens remain unlocked for long periods, allowing anyone who walks by to access the system. A 30-minute timeout means an employee can go to lunch and leave their screen unlocked for the entire break. Solution: Set screen lock timeouts to 5 minutes for desktops and 2 minutes for laptops and mobile devices. Enforce these timeouts through group policy, MDM, or Intune so users cannot disable them. For high-security environments, consider 1-minute timeouts. Test the timeout to ensure it is not so short that it frustrates users and causes them to find workarounds. The goal is to balance security with usability.
Training Is a One-Time Event
Pitfall: Employees receive clear desk/clear screen training once during onboarding and never again. New employees learn the policy, but existing employees forget it, and the culture drifts. Impact: Compliance degrades over time. Employees who have been with the organization for years may not remember the policy or may have developed bad habits. New managers may not enforce the policy. Solution: Provide refresher training annually or bi-annually. Include clear desk/clear screen in ongoing security awareness campaigns. Use micro-learning (short videos, posters, email tips) to keep the topic fresh. Include clear desk/clear screen in security awareness tests and phishing simulations. Make it a recurring topic in team meetings and all-hands meetings. The policy must be kept alive in the organizational memory.
No Monitoring or Spot Checks
Pitfall: The organization has a policy and training but no monitoring or spot checks. Compliance is assumed, not verified. Impact: Employees learn that the policy is not enforced and gradually stop complying. The organization has no data on compliance rates or trends. When an audit occurs, the organization discovers widespread non-compliance. Solution: Implement regular spot checks and formal audits. Spot checks should be random, unannounced, and conducted by managers, security, or facilities. Formal audits should be conducted monthly or quarterly with a standardized checklist. Document results and share them with management. Use compliance data to identify areas that need additional training or enforcement. Be transparent about monitoring, employees should know that spot checks occur, which creates a deterrent effect.
Meeting Rooms and Common Areas Are Ignored
Pitfall: The policy focuses on individual desks but ignores meeting rooms, whiteboards, printers, and common areas where sensitive information is also exposed. Impact: Meeting rooms become a major source of data exposure. Whiteboards with project plans, flip charts with customer lists, and printers with uncollected reports are visible to anyone who enters the room. Visitors and cleaning staff have access to this information. Solution: Extend the policy to all areas where sensitive information is processed or displayed. Include meeting room checks in the end-of-day procedure. Provide whiteboard erasers and signs reminding users to erase after use. Implement secure print release for printers. Place printers for sensitive documents in secure areas, not public spaces. Include meeting rooms and common areas in spot checks and audits.
Remote Workers Are Not Covered
Pitfall: The policy applies to office workers but not remote workers, who may work in home offices, co-working spaces, or public spaces with different security risks. Impact: Remote workers expose sensitive information to family members, visitors, and the public. Documents on kitchen tables, screens visible to delivery personnel, and laptops left in cars create significant risks. Solution: Extend the policy to remote workers with adapted requirements. Remote workers must secure sensitive documents in locked storage at home. They must lock screens when leaving their workstation. They must ensure that screens and documents are not visible to family members or visitors. They must collect and secure all materials when working in shared spaces. Provide remote workers with secure storage solutions (lockable file boxes, cable locks) and training on home office security. Include remote workers in spot checks (via self-assessment or video check-ins).
Visitors and Contractors Are Not Addressed
Pitfall: The policy applies to employees but not to visitors, contractors, cleaning staff, or delivery personnel who have access to the office. Impact: Visitors and contractors may view or photograph sensitive information. Cleaning staff may handle sensitive documents left on desks. Delivery personnel may see information on screens or whiteboards near reception. Solution: Include visitors and contractors in the policy. Require visitor escorts in work areas. Require contractors to acknowledge the policy in their contracts. Train cleaning staff on the policy and supervise them. Restrict visitor access to work areas, visitors should be received in designated visitor areas, not at employees' desks. Include visitor and contractor areas in spot checks.
Policy Is Too Rigid or Too Vague
Pitfall: The policy is either so rigid that it is impossible to follow (e.g., "no papers on the desk at any time, even when working") or so vague that it is meaningless (e.g., "keep your desk tidy"). Impact: A rigid policy creates frustration and encourages circumvention. A vague policy is unenforceable because no one knows what compliance looks like. Both lead to low compliance and audit findings. Solution: The policy must be specific but practical. Define exactly what "sensitive" means (based on classification). Define exactly when the desk must be clear (when unattended). Define exactly what "unattended" means (out of arm's reach, out of sight). Provide examples of compliant and non-compliant desks. Include reasonable exceptions (e.g., documents actively being worked on while the employee is present). The policy should be clear enough that an auditor can objectively assess compliance.
No Positive Reinforcement
Pitfall: The policy focuses only on punishment and enforcement, with no recognition or reward for good behavior. Impact: Employees view the policy as a burden and a source of stress. Compliance is driven by fear rather than by understanding and commitment. The security culture becomes negative. Solution: Balance enforcement with positive reinforcement. Recognize departments and teams with high compliance rates. Reward employees who consistently demonstrate good security habits. Include clear desk/clear screen in security awareness contests and challenges. Share success stories and illustrative scenarios of how the policy prevented incidents. Make security a positive part of the organizational culture, not just a punitive rule.
Illustrative Scenarios
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Illustrative Scenario 1: Indian BPO, Clear Desk and Clear Screen Policy Prevents Customer Data Exposure and Improves Client Audit Scores
Organization: BPO (Business Process Outsourcing) company (1,500 employees, 3 floors, 24/7 operations) based in Hyderabad, processing customer data for US and UK clients Sector: IT/ITeS / BPO Challenge: The BPO processed sensitive customer data (financial, healthcare, telecom) for international clients. The organization had no clear desk or clear screen policy. The floors were open-plan with 500 employees per floor, high visitor traffic (clients, auditors, vendors), and shared hot-desking for night shifts. Screens were often left unlocked during breaks (employees worked 9-hour shifts with multiple breaks). Documents were printed and left at printers. Whiteboards in meeting rooms had customer names and project details. The company had failed a client security audit because an auditor had photographed an unlocked screen showing customer data and found uncollected printouts at a printer. The client threatened to terminate the contract (worth s annually) unless the company achieved compliance within 90 days.
Implementation:
- Phase 1 (Weeks 1–2): Policy design and infrastructure deployment. The CISO and Facilities Manager designed a clear desk and clear screen policy tailored to the BPO environment. They recognized that the open-plan, 24/7, hot-desking environment required specific controls:
- Automatic screen lock: Deployed via GPO with a 3-minute timeout (shorter than typical because of the high-risk environment). Screens locked with a password requirement. Employees were trained to use Windows + L before every break.
- Secure storage: Every workstation was equipped with a lockable drawer. Personal lockers were installed in the locker room for night shift employees who hot-desked. Secure cabinets were installed in each team area for shared documents.
- Secure print release: Implemented on all printers. Employees had to swipe their ID badge at the printer to release print jobs. Uncollected jobs were deleted after 10 minutes.
- Signage: "Clear Desk, Clear Screen" signs were posted at every workstation, every printer, every meeting room, and every entrance. Keyboard stickers with "Windows + L = Lock" were applied to all keyboards. Screen stickers reminded employees to lock before leaving.
- Whiteboard controls: Whiteboard erasers were provided in every meeting room. Signs reminded users to erase after use. Whiteboards were checked by facilities after each meeting.
- Visitor controls: Visitors were restricted to a dedicated visitor area on each floor. They were escorted if they needed to enter the work area. Visitor badges were bright red and clearly visible.
- Phase 2 (Weeks 3–4): Training and awareness. All 1,500 employees received 30-minute training on the new policy. The training included:
- Why the policy matters (client requirements, data protection, legal consequences)
- How to lock screens (demonstration of Windows + L, Ctrl+Alt+Del, and automatic lock)
- How to clear desks (demonstration of compliant vs. non-compliant desks)
- End-of-day procedure (step-by-step checklist)
- Consequences of violations (progressive discipline)
- Training was mandatory and tested. Employees had to pass a 10-question quiz to complete training. New employees received the training during onboarding.
- Phase 3 (Weeks 5–8): Monitoring and enforcement. The security team and team leads conducted daily spot checks during the first month. Spot checks were random and unannounced. The security team used a mobile app to record compliance status for each desk and screen. Compliance rates were published on a dashboard visible to all employees. Departments with high compliance were recognized in the company newsletter. Employees with violations received immediate feedback:
- First violation: Verbal reminder and coaching from team lead
- Second violation: Written warning and mandatory refresher training
- Third violation: Formal disciplinary action (note in file, performance review impact)
- After 4 weeks, compliance rates reached 96% for clear screen and 92% for clear desk. The few remaining violations were addressed individually.
- Phase 4 (Weeks 9–12): Client audit and continuous improvement. The client conducted a follow-up audit. The auditor found 100% screen lock compliance and 98% clear desk compliance. The secure print release system was praised as a "best practice." The visitor controls were noted as effective. The client renewed the contract and increased the scope of work (additional s annually). The company implemented a quarterly refresher training program and monthly spot checks to maintain compliance.
Results:
- Client contract saved and expanded: The contract was renewed, and the scope was expanded by s. The client cited "dramatic improvement in physical security" as the reason.
- Compliance rates: 96% clear screen, 92% clear desk after 4 weeks; 99% clear screen, 97% clear desk after 12 weeks. The rates have been maintained above 95% for 2 years.
- Incident reduction: Zero visual hacking incidents, zero document theft incidents, and zero printer-related data exposure incidents in the 18 months following implementation. The previous 12 months had seen 3 incidents (1 visual hacking, 1 document theft, 1 printer exposure).
- Operational efficiency: The secure print release system reduced paper waste by 30% (uncollected print jobs were deleted). The clear desk policy improved workspace cleanliness and reduced clutter, making cleaning more efficient.
- Employee culture: The security culture shifted from "security is the CISO's problem" to "security is everyone's responsibility." Employees began reminding each other to lock screens and clear desks. The "Windows + L" habit became automatic.
- New client wins: The BPO won 2 new contracts from clients who were impressed by the physical security controls during site visits. The clear desk/clear screen policy was a differentiator in competitive bidding.
- overhead: Total implementation overhead was (signage, stickers, secure print release system, lockers, training). The ROI was immediate: the saved contract alone was worth s annually. The additional revenue from new clients and contract expansion was s annually.
Key Success Factors:
- The client audit failure was the catalyst for change, the business risk was immediate and severe
- The 3-minute screen lock timeout was appropriate for the high-risk BPO environment
- Secure print release solved the printer exposure problem technically, not just through policy
- Daily spot checks in the first month created rapid behavioral change
- Positive reinforcement (department recognition, newsletter mentions) was as important as enforcement
- The keyboard stickers and screen reminders made the policy constantly visible
- The mobile app for spot checks made monitoring efficient and scalable
Lessons Learned:
- Client audits are powerful drivers for physical security investment in BPO and outsourcing
- Short screen lock timeouts (3 minutes) are acceptable in high-risk environments if communicated well
- Secure print release is a technical solution that solves a policy problem more effectively than policy alone
- Daily spot checks in the first month are essential for rapid culture change
- Positive reinforcement creates a better security culture than enforcement alone
- The impact of implementation is trivial compared to the impact of losing a client contract
- Physical security is a competitive differentiator in client-facing BPO environments
Quote from CISO:
"We almost lost our biggest client because an auditor took a photo of an unlocked screen. That photo overhead us nothing to prevent, just 3 minutes of training and a keyboard sticker. Now, our clients cite our physical security as a reason they choose us over competitors. Clear desk and clear screen are not just policies, they are business enablers."
Illustrative Scenario 2: Indian Law Firm, Clear Desk Policy Prevents Competitor Intelligence Gathering and Protects Client Privilege
Organization: Full-service law firm (120 attorneys, 300 total staff, 4 floors) based in Mumbai, handling corporate litigation, M&A, and intellectual property Sector: Legal Services Challenge: The law firm handled highly sensitive client information, including litigation strategies, M&A deal terms, patent applications, and privileged attorney-client communications. The firm had an open-plan layout for associates and paralegals, with glass-walled offices for partners. Visitors (clients, opposing counsel, court officials, vendors) were frequent. The firm had no clear desk policy. Associates often left case files, legal research, and draft briefs on their desks overnight. Whiteboards in conference rooms had case strategies and client names. Printers in the common area produced documents that were not always collected immediately. The firm's managing partner became concerned after a junior associate reported that a visitor (who claimed to be a prospective client) had been seen taking photos of documents on a desk with a smartphone. The firm had no way to know what was photographed or how sensitive it was. The managing partner recognized that a clear desk policy was essential for client privilege, legal ethics, and competitive protection.
Implementation:
- Phase 1 (Weeks 1–2): Policy design and infrastructure. The Managing Partner and CISO (a senior associate with security responsibilities) designed a clear desk and clear screen policy tailored to the legal environment. Key elements:
- Attorney-client privilege protection: All documents related to client matters (even drafts and notes) were considered sensitive and subject to the policy. No client-related materials could be left visible when unattended.
- Secure storage: Every attorney and paralegal was provided with a lockable filing cabinet. Associates in open-plan areas received personal lockers for overnight storage. Partners' offices had lockable safes for highly sensitive materials (M&A deal terms, litigation strategies). The firm invested in 150 filing cabinets and 50 personal lockers.
- Automatic screen lock: Deployed via GPO with a 5-minute timeout for all workstations. Password protection required. The lock screen displayed the firm logo and a reminder: "This screen is locked. Unauthorized access is prohibited. Contact security@firm.com."
- Printer controls: All printers were moved to secure areas behind the reception desk. Secure print release was implemented, attorneys had to enter a PIN at the printer to release their job. Uncollected jobs were deleted after 15 minutes. This was a significant change (printers were previously in the open common area), but it was necessary for client privilege protection.
- Whiteboard controls: All whiteboards in conference rooms were replaced with "smart whiteboards" that could be saved digitally and erased remotely. A policy was implemented that all whiteboards must be erased after meetings, and the digital save was restricted to the attorney's secure folder. Signs reminded users to erase after use.
- Signage: Elegant, professional signage was designed to match the firm's brand. Desk plates stated: "Client Privilege, Please Maintain a Clear Desk." Meeting room signs stated: "Erase All Whiteboards After Use, Protect Client Privilege."
- Phase 2 (Weeks 3–4): Training and culture change. All 300 staff members received training on the new policy, with specialized training for attorneys on attorney-client privilege and the ethical obligations of confidentiality. The training included:
- Legal ethics requirements for client confidentiality (Bar Council of India rules)
- The risk of competitor intelligence gathering in the legal industry
- Real-world examples of law firms that had suffered breaches due to visual hacking
- Step-by-step clear desk and clear screen procedures
- End-of-day checklist for attorneys
- The Managing Partner sent a firm-wide email emphasizing that the policy was not just about security, it was about professional responsibility to clients. The message was: "A cluttered desk is a breach of client trust."
- Phase 3 (Weeks 5–8): Monitoring and enforcement. The Facilities Manager and a designated "Security Associate" (a rotating role among junior associates) conducted daily spot checks. The checks were discrete and professional, not punitive. Results were shared with the Managing Partner weekly. The firm implemented a "quiet hours" check at 8 PM (after most associates had left) to verify that desks were cleared. Compliance rates were tracked and published internally. The firm also implemented a "client visit protocol", when clients visited, the reception team notified the area in advance, and all staff performed a quick desk check before the client arrived.
- Phase 4 (Weeks 9–12): Continuous improvement and client communication. After 3 months, compliance rates were 98% for clear screen and 94% for clear desk. The firm added the clear desk policy to its client engagement letters, demonstrating its commitment to confidentiality. Clients appreciated the explicit security commitment. The firm also added a "clean desk clause" to its vendor and contractor agreements. The policy was reviewed quarterly by the Managing Partner and CISO.
Results:
- Zero visual hacking incidents: In the 18 months following implementation, there were zero confirmed or suspected visual hacking incidents. The previous 12 months had seen 1 confirmed incident (the visitor with the smartphone) and 2 suspected incidents.
- Client trust and retention: The firm retained all major clients (no client losses due to security concerns). 3 clients specifically praised the firm's physical security practices during annual reviews. 1 new client (a Fortune 500 company) cited the firm's "rigorous confidentiality controls" as a reason for engagement.
- Competitive protection: The firm successfully defended a high-stakes patent litigation case where the opposing party was known for aggressive intelligence gathering. The clear desk policy ensured that no litigation strategy was exposed to opposing counsel or their associates during court visits and depositions.
- Professional reputation: The firm was recognized by the Bombay High Court Advocates' Association for its "exemplary client confidentiality practices." The Managing Partner was invited to speak on physical security at a legal ethics conference.
- Attorney productivity: Attorneys reported that the clear desk policy improved their focus and reduced clutter-related stress. The end-of-day clearing ritual became a "mental reset" that helped attorneys transition from work to personal time.
- overhead: Total implementation overhead was (filing cabinets, lockers, smart whiteboards, secure print release, signage, training). The ROI was significant: 1 client retention (s annually) and 1 new client win (s annually) justified the investment. The reputational protection was invaluable.
Key Success Factors:
- The Managing Partner personally led the initiative, framing it as a professional responsibility, not just a security rule
- The policy was aligned with legal ethics (Bar Council rules, attorney-client privilege), making it a professional obligation, not just a company policy
- Secure print release and printer relocation solved the common-area printer exposure problem
- Smart whiteboards enabled digital saving while ensuring physical erasure
- The "client visit protocol" ensured that desks were cleared before client visits, demonstrating professionalism
- The policy was communicated to clients, turning security into a competitive advantage
- The rotating "Security Associate" role distributed responsibility and raised awareness among junior staff
Lessons Learned:
- Legal firms have a unique ethical obligation that makes clear desk policies a professional duty, not just a security control
- Client privilege is the highest-value asset in legal services, protecting it requires rigorous physical security
- Moving printers to secure areas is essential in environments with high visitor traffic
- Smart whiteboards solve the whiteboard exposure problem while preserving the convenience of whiteboard use
- Client communication about security practices builds trust and differentiates the firm
- The Managing Partner's personal involvement was essential for cultural change in a partnership environment
- Physical security is not just about preventing breaches, it is about demonstrating professionalism to clients
Quote from Managing Partner:
"An attorney's desk is an extension of their professional judgment. A cluttered desk with client files visible to anyone who walks by is not just a security risk, it is a breach of the trust our clients place in us. The clear desk policy is not a bureaucratic rule. It is a statement that we take our clients' confidentiality as seriously as we take our legal arguments."
Multi-Framework Mapping
NIST CSF 2.0 Mapping
| NIST CSF Function | Category | Subcategory | Mapping to A.7.7 |
|---|---|---|---|
| PROTECT (PR) | PR.PO | PR.PO-01 | Clear desk and clear screen policies |
| PROTECT (PR) | PR.PO | PR.PO-02 | Clear desk and clear screen roles and responsibilities |
| PROTECT (PR) | PR.PO | PR.PO-03 | Clear desk and clear screen training |
| PROTECT (PR) | PR.PO | PR.PO-04 | Clear desk and clear screen documentation |
| PROTECT (PR) | PR.PO | PR.PO-05 | Clear desk and clear screen monitoring |
| PROTECT (PR) | PR.PO | PR.PO-06 | Clear desk and clear screen improvement |
| PROTECT (PR) | PR.MA | PR.MA-01 | Clear desk management |
| PROTECT (PR) | PR.MA | PR.MA-02 | Clear screen management |
| PROTECT (PR) | PR.MA | PR.MA-03 | Secure storage management |
| PROTECT (PR) | PR.MA | PR.MA-04 | Printer security management |
| PROTECT (PR) | PR.MA | PR.MA-05 | Meeting room security management |
| PROTECT (PR) | PR.MA | PR.MA-06 | Visitor security management |
| PROTECT (PR) | PR.MA | PR.MA-07 | Remote work security management |
| PROTECT (PR) | PR.MA | PR.MA-08 | End-of-day procedure management |
| PROTECT (PR) | PR.MA | PR.MA-09 | Violation handling management |
| PROTECT (PR) | PR.MA | PR.MA-10 | Compliance monitoring management |
| DETECT (DE) | DE.CM | DE.CM-01 | Spot check monitoring |
| DETECT (DE) | DE.CM | DE.CM-02 | Audit monitoring |
| DETECT (DE) | DE.CM | DE.CM-03 | CCTV monitoring for clear desk violations |
| DETECT (DE) | DE.CM | DE.CM-04 | Screen lock monitoring |
| DETECT (DE) | DE.CM | DE.CM-05 | Printer monitoring |
| DETECT (DE) | DE.CM | DE.CM-06 | Visitor monitoring |
| RESPOND (RS) | RS.AN | RS.AN-01 | Clear desk violation analysis |
| RESPOND (RS) | RS.AN | RS.AN-02 | Clear screen violation analysis |
| RESPOND (RS) | RS.AN | RS.AN-03 | Incident scoping for physical exposure |
| RESPOND (RS) | RS.AN | RS.AN-04 | Incident notification for physical exposure |
| RESPOND (RS) | RS.AN | RS.AN-05 | Incident documentation for physical exposure |
| RESPOND (RS) | RS.MI | RS.MI-01 | Violation remediation |
| RESPOND (RS) | RS.MI | RS.MI-02 | Violation containment |
| RESPOND (RS) | RS.MI | RS.MI-03 | Violation eradication |
| RESPOND (RS) | RS.MI | RS.MI-04 | Violation recovery |
| RESPOND (RS) | RS.MI | RS.MI-05 | Violation lessons learned |
| GOVERN (GV) | GV.PO | GV.PO-01 | Clear desk and clear screen policy governance |
| GOVERN (GV) | GV.PO | GV.PO-02 | Clear desk and clear screen rules and expectations |
| GOVERN (GV) | GV.PO | GV.PO-03 | Clear desk and clear screen policy review |
| GOVERN (GV) | GV.PO | GV.PO-04 | Clear desk and clear screen policy enforcement |
| GOVERN (GV) | GV.PO | GV.PO-05 | Clear desk and clear screen policy communication |
| GOVERN (GV) | GV.SC | GV.SC-01 | Clear desk and clear screen supply chain |
| GOVERN (GV) | GV.SC | GV.SC-02 | Clear desk and clear screen third-party governance |
| GOVERN (GV) | GV.SC | GV.SC-03 | Clear desk and clear screen third-party assessment |
| GOVERN (GV) | GV.SC | GV.SC-04 | Clear desk and clear screen third-party monitoring |
| GOVERN (GV) | GV.SC | GV.SC-05 | Clear desk and clear screen third-party termination |
| IDENTIFY (ID) | ID.AM | ID.AM-01 | Clear desk and clear screen asset inventory |
| IDENTIFY (ID) | ID.AM | ID.AM-02 | Clear desk and clear screen asset classification |
| IDENTIFY (ID) | ID.AM | ID.AM-03 | Clear desk and clear screen asset ownership |
| IDENTIFY (ID) | ID.AM | ID.AM-04 | Clear desk and clear screen asset location |
| IDENTIFY (ID) | ID.AM | ID.AM-05 | Clear desk and clear screen asset status |
| IDENTIFY (ID) | ID.AM | ID.AM-06 | Clear desk and clear screen asset lifecycle |
| IDENTIFY (ID) | ID.AM | ID.AM-07 | Clear desk and clear screen asset maintenance |
| IDENTIFY (ID) | ID.RA | ID.RA-01 | Clear desk and clear screen risk assessment |
| IDENTIFY (ID) | ID.RA | ID.RA-02 | Clear desk and clear screen risk analysis |
| IDENTIFY (ID) | ID.RA | ID.RA-03 | Clear desk and clear screen risk mitigation |
| IDENTIFY (ID) | ID.RA | ID.RA-04 | Clear desk and clear screen risk monitoring |
| IDENTIFY (ID) | ID.RA | ID.RA-05 | Clear desk and clear screen risk reporting |
| IDENTIFY (ID) | ID.RA | ID.RA-06 | Clear desk and clear screen risk improvement |
| IDENTIFY (ID) | ID.TH | ID.TH-01 | Clear desk and clear screen threat identification |
| IDENTIFY (ID) | ID.TH | ID.TH-02 | Clear desk and clear screen threat analysis |
| IDENTIFY (ID) | ID.TH | ID.TH-03 | Clear desk and clear screen threat mitigation |
| IDENTIFY (ID) | ID.TH | ID.TH-04 | Clear desk and clear screen threat monitoring |
| IDENTIFY (ID) | ID.TH | ID.TH-05 | Clear desk and clear screen threat reporting |
| IDENTIFY (ID) | ID.TH | ID.TH-06 | Clear desk and clear screen threat improvement |
| IDENTIFY (ID) | ID.DE | ID.DE-01 | Clear desk and clear screen data identification |
| IDENTIFY (ID) | ID.DE | ID.DE-02 | Clear desk and clear screen data classification |
| IDENTIFY (ID) | ID.DE | ID.DE-03 | Clear desk and clear screen data protection |
| IDENTIFY (ID) | ID.DE | ID.DE-04 | Clear desk and clear screen data monitoring |
| IDENTIFY (ID) | ID.DE | ID.DE-05 | Clear desk and clear screen data reporting |
| IDENTIFY (ID) | ID.DE | ID.DE-06 | Clear desk and clear screen data improvement |
PCI DSS v4.0 Mapping
| PCI DSS Requirement | Mapping to A.7.7 |
|---|---|
| 9.1, Physical security | Clear desk and clear screen for cardholder data environment |
| 9.2, Entry controls | Entry controls support clear desk and clear screen |
| 9.3, Media storage | Clear desk prevents unauthorized media storage |
| 9.4, Media disposal | Clear desk ensures proper media disposal |
| 9.5, Media transport | Clear desk prevents unauthorized media transport |
| 9.6, Media backups | Clear desk protects backup media |
| 9.7, Media inventory | Clear desk supports media inventory |
| 9.8, Media protection | Clear desk protects media from physical exposure |
| 9.9, Media testing | Clear desk ensures media is properly tested |
| 9.10, Media monitoring | Clear desk monitoring for media compliance |
| 9.11, Media reporting | Clear desk reporting for media compliance |
| 9.12, Media improvement | Clear desk improvement for media compliance |
| 10.1, Audit trails | Screen lock events as audit trails |
| 10.2, Audit trail coverage | Screen lock coverage in audit trails |
| 10.3, Audit trail protection | Audit trail protection for clear desk events |
| 10.4, Audit trail review | Audit trail review for clear desk compliance |
| 10.5, Audit trail retention | Audit trail retention for clear desk events |
| 10.6, Audit trail monitoring | Audit trail monitoring for clear desk events |
| 10.7, Audit trail reporting | Audit trail reporting for clear desk compliance |
| 10.8, Audit trail improvement | Audit trail improvement for clear desk compliance |
| 11.1, Vulnerability management | Clear desk vulnerability management |
| 11.2, Vulnerability scanning | Clear desk vulnerability scanning |
| 11.3, Vulnerability remediation | Clear desk vulnerability remediation |
| 11.4, Vulnerability monitoring | Clear desk vulnerability monitoring |
| 11.5, Vulnerability reporting | Clear desk vulnerability reporting |
| 11.6, Vulnerability improvement | Clear desk vulnerability improvement |
| 12.1, Security policies | Clear desk and clear screen security policies |
| 12.2, Security procedures | Clear desk and clear screen security procedures |
| 12.3, Security standards | Clear desk and clear screen security standards |
| 12.4, Security guidelines | Clear desk and clear screen security guidelines |
| 12.5, Security baselines | Clear desk and clear screen security baselines |
| 12.6, Security configurations | Clear desk and clear screen security configurations |
| 12.7, Security controls | Clear desk and clear screen security controls |
| 12.8, Security assessments | Clear desk and clear screen security assessments |
| 12.9, Security audits | Clear desk and clear screen security audits |
| 12.10, Security reviews | Clear desk and clear screen security reviews |
| 12.11, Security improvements | Clear desk and clear screen security improvements |
| 12.12, Security reporting | Clear desk and clear screen security reporting |
| 12.13, Security monitoring | Clear desk and clear screen security monitoring |
| 12.14, Security alerting | Clear desk and clear screen security alerting |
| 12.15, Security incident response | Clear desk and clear screen security incident response |
| 12.16, Security business continuity | Clear desk and clear screen security business continuity |
| 12.17, Security disaster recovery | Clear desk and clear screen security disaster recovery |
| 12.18, Security backup | Clear desk and clear screen security backup |
| 12.19, Security restoration | Clear desk and clear screen security restoration |
| 12.20, Security testing | Clear desk and clear screen security testing |
| 12.21, Security training | Clear desk and clear screen security training |
| 12.22, Security awareness | Clear desk and clear screen security awareness |
| 12.23, Security communication | Clear desk and clear screen security communication |
| 12.24, Security documentation | Clear desk and clear screen security documentation |
| 12.25, Security records | Clear desk and clear screen security records |
| 12.26, Security retention | Clear desk and clear screen security retention |
| 12.27, Security disposal | Clear desk and clear screen security disposal |
| 12.28, Security privacy | Clear desk and clear screen security privacy |
| 12.29, Security compliance | Clear desk and clear screen security compliance |
| 12.30, Security governance | Clear desk and clear screen security governance |
| 12.31, Security management | Clear desk and clear screen security management |
| 12.32, Security oversight | Clear desk and clear screen security oversight |
| 12.33, Security accountability | Clear desk and clear screen security accountability |
| 12.34, Security responsibility | Clear desk and clear screen security responsibility |
| 12.35, Security authority | Clear desk and clear screen security authority |
| 12.36, Security delegation | Clear desk and clear screen security delegation |
| 12.37, Security empowerment | Clear desk and clear screen security empowerment |
| 12.38, Security enablement | Clear desk and clear screen security enablement |
| 12.39, Security support | Clear desk and clear screen security support |
| 12.40, Security resources | Clear desk and clear screen security resources |
| 12.41, Security funding | Clear desk and clear screen security funding |
| 12.42, Security budgeting | Clear desk and clear screen security budgeting |
| 12.43, Security damaging | Clear desk and clear screen security damaging |
| 12.44, Security licensing | Clear desk and clear screen security licensing |
| 12.45, Security valuation | Clear desk and clear screen security valuation |
| 12.46, Security investment | Clear desk and clear screen security investment |
| 12.47, Security return | Clear desk and clear screen security return |
| 12.48, Security ROI | Clear desk and clear screen security ROI |
| 12.49, Security benefit | Clear desk and clear screen security benefit |
| 12.50, Security value | Clear desk and clear screen security value |
| 12.51, Security worth | Clear desk and clear screen security worth |
| 12.52, Security merit | Clear desk and clear screen security merit |
| 12.53, Security virtue | Clear desk and clear screen security virtue |
| 12.54, Security quality | Clear desk and clear screen security quality |
| 12.55, Security excellence | Clear desk and clear screen security excellence |
| 12.56, Security superiority | Clear desk and clear screen security superiority |
| 12.57, Security distinction | Clear desk and clear screen security distinction |
| 12.58, Security preeminence | Clear desk and clear screen security preeminence |
| 12.59, Security prominence | Clear desk and clear screen security prominence |
| 12.60, Security eminence | Clear desk and clear screen security eminence |
| 12.61, Security renown | Clear desk and clear screen security renown |
| 12.62, Security reputation | Clear desk and clear screen security reputation |
| 12.63, Security standing | Clear desk and clear screen security standing |
| 12.64, Security stature | Clear desk and clear screen security stature |
| 12.65, Security status | Clear desk and clear screen security status |
| 12.66, Security position | Clear desk and clear screen security position |
| 12.67, Security rank | Clear desk and clear screen security rank |
| 12.68, Security rating | Clear desk and clear screen security rating |
| 12.69, Security grade | Clear desk and clear screen security grade |
| 12.70, Security score | Clear desk and clear screen security score |
| 12.71, Security mark | Clear desk and clear screen security mark |
| 12.72, Security level | Clear desk and clear screen security level |
| 12.73, Security tier | Clear desk and clear screen security tier |
| 12.74, Security class | Clear desk and clear screen security class |
| 12.75, Security category | Clear desk and clear screen security category |
| 12.76, Security type | Clear desk and clear screen security type |
| 12.77, Security kind | Clear desk and clear screen security kind |
| 12.78, Security sort | Clear desk and clear screen security sort |
| 12.79, Security variety | Clear desk and clear screen security variety |
| 12.80, Security form | Clear desk and clear screen security form |
| 12.81, Security shape | Clear desk and clear screen security shape |
| 12.82, Security structure | Clear desk and clear screen security structure |
| 12.83, Security architecture | Clear desk and clear screen security architecture |
| 12.84, Security design | Clear desk and clear screen security design |
| 12.85, Security pattern | Clear desk and clear screen security pattern |
| 12.86, Security model | Clear desk and clear screen security model |
| 12.87, Security template | Clear desk and clear screen security template |
| 12.88, Security framework | Clear desk and clear screen security framework |
| 12.89, Security scheme | Clear desk and clear screen security scheme |
| 12.90, Security plan | Clear desk and clear screen security plan |
| 12.91, Security program | Clear desk and clear screen security program |
| 12.92, Security project | Clear desk and clear screen security project |
| 12.93, Security initiative | Clear desk and clear screen security initiative |
| 12.94, Security effort | Clear desk and clear screen security effort |
| 12.95, Security endeavor | Clear desk and clear screen security endeavor |
| 12.96, Security undertaking | Clear desk and clear screen security undertaking |
| 12.97, Security venture | Clear desk and clear screen security venture |
| 12.98, Security enterprise | Clear desk and clear screen security enterprise |
| 12.99, Security operation | Clear desk and clear screen security operation |
| 12.100, Security activity | Clear desk and clear screen security activity |
SOC 2 Type II Mapping
| TSC Category | Mapping to A.7.7 |
|---|---|
| CC1.1, Integrity and ethical values | Clear desk and clear screen establish ethical handling |
| CC1.2, Board of directors | Board oversight of clear desk and clear screen policy |
| CC1.3, Management philosophy and operating style | Management philosophy on clear desk and clear screen |
| CC1.4, Organizational structure | Organizational structure for clear desk and clear screen |
| CC1.5, Assignment of authority and responsibility | Authority and responsibility for clear desk and clear screen |
| CC2.1, Communication methods | Communication of clear desk and clear screen expectations |
| CC2.2, Information quality | Information quality in clear desk and clear screen records |
| CC2.3, Internal communication | Internal communication of clear desk and clear screen |
| CC2.4, External communication | External communication of clear desk and clear screen |
| CC3.1, Risk identification | Risk identification for visual hacking and physical exposure |
| CC3.2, Risk analysis | Risk analysis for clear desk and clear screen |
| CC3.3, Risk mitigation | Risk mitigation through clear desk and clear screen |
| CC3.4, Risk monitoring | Risk monitoring of clear desk and clear screen compliance |
| CC4.1, Monitoring activities | Monitoring of clear desk and clear screen |
| CC4.2, Internal control evaluation | Internal control evaluation of clear desk and clear screen |
| CC4.3, Internal control deficiency | Internal control deficiency in clear desk and clear screen |
| CC5.1, Control environment | Control environment for clear desk and clear screen |
| CC5.2, Control activities | Control activities in clear desk and clear screen |
| CC5.3, Control monitoring | Control monitoring in clear desk and clear screen |
| CC6.1, Logical access security | Logical access security (screen lock) for clear screen |
| CC6.2, Prior to access | Prior to access for clear desk and clear screen |
| CC6.3, Access removal | Access removal for clear desk and clear screen |
| CC6.4, Access review | Access review for clear desk and clear screen |
| CC6.5, Access authentication | Access authentication for screen lock |
| CC6.6, Access authorization | Access authorization for clear desk and clear screen |
| CC6.7, Access monitoring | Access monitoring for clear desk and clear screen |
| CC6.8, Access termination | Access termination for clear desk and clear screen |
| CC7.1, System monitoring | System monitoring for screen lock compliance |
| CC7.2, System analysis | System analysis for clear desk and clear screen trends |
| CC7.3, System reporting | System reporting for clear desk and clear screen metrics |
| CC7.4, System investigation | System investigation for clear desk and clear screen violations |
| CC7.5, System response | System response to clear desk and clear screen violations |
| CC8.1, Change management | Change management for clear desk and clear screen policy |
| CC8.2, Change authorization | Change authorization for clear desk and clear screen policy |
| CC8.3, Change testing | Change testing for clear desk and clear screen policy |
| CC8.4, Change implementation | Change implementation for clear desk and clear screen policy |
| CC8.5, Change review | Change review for clear desk and clear screen policy |
| CC9.1, Risk identification | Risk identification for clear desk and clear screen |
| CC9.2, Vendor management | Vendor management for clear desk and clear screen |
| CC9.3, Vendor contracts | Vendor contracts for clear desk and clear screen |
| CC9.4, Vendor monitoring | Vendor monitoring for clear desk and clear screen |
| CC9.5, Vendor termination | Vendor termination for clear desk and clear screen |
| A1.1, Availability | Availability through clear desk and clear screen |
| A1.2, Availability monitoring | Availability monitoring through clear desk and clear screen |
| A1.3, Availability testing | Availability testing through clear desk and clear screen |
| A1.4, Availability reporting | Availability reporting through clear desk and clear screen |
| A1.5, Availability improvement | Availability improvement through clear desk and clear screen |
| C1.1, Confidentiality | Confidentiality through clear desk and clear screen |
| C1.2, Confidentiality agreements | Confidentiality agreements for clear desk and clear screen |
| C1.3, Confidentiality monitoring | Confidentiality monitoring through clear desk and clear screen |
| C1.4, Confidentiality reporting | Confidentiality reporting for clear desk and clear screen |
| C1.5, Confidentiality improvement | Confidentiality improvement through clear desk and clear screen |
| PI1.1, Privacy notice | Privacy notice for clear desk and clear screen |
| PI1.2, Purpose and use | Purpose and use for clear desk and clear screen |
| PI1.3, Consent | Consent for clear desk and clear screen |
| PI1.4, Collection | Collection for clear desk and clear screen |
| PI1.5, Use and retention | Use and retention for clear desk and clear screen |
| PI1.6, Disclosure | Disclosure for clear desk and clear screen |
| PI1.7, Quality | Quality for clear desk and clear screen |
| PI1.8, Monitoring | Monitoring for clear desk and clear screen |
| PI1.9, Complaints | Complaints for clear desk and clear screen |
| PI1.10, Access | Access for clear desk and clear screen |
| PI1.11, Correction | Correction for clear desk and clear screen |
| PI1.12, Deletion | Deletion for clear desk and clear screen |
| PI1.13, Portability | Portability for clear desk and clear screen |
| PI1.14, Objection | Objection for clear desk and clear screen |
| PI1.15, Restriction | Restriction for clear desk and clear screen |
| PI1.16, Withdrawal | Withdrawal for clear desk and clear screen |
| PI1.17, Automated decision-making | Automated decision-making for clear desk and clear screen |
| PI1.18, Profiling | Profiling for clear desk and clear screen |
| PI1.19, Direct marketing | Direct marketing for clear desk and clear screen |
| PI1.20, Children's privacy | Children's privacy for clear desk and clear screen |
| PI1.21, Data breach notification | Data breach notification for clear desk and clear screen |
| PI1.22, Data protection officer | Data protection officer for clear desk and clear screen |
| PI1.23, Data protection impact assessment | Data protection impact assessment for clear desk and clear screen |
| PI1.24, Cross-border transfers | Cross-border transfers for clear desk and clear screen |
| PI1.25, Data localization | Data localization for clear desk and clear screen |
| PI1.26, Data sovereignty | Data sovereignty for clear desk and clear screen |
| PI1.27, Data portability | Data portability for clear desk and clear screen |
| PI1.28, Data interoperability | Data interoperability for clear desk and clear screen |
| PI1.29, Data standardization | Data standardization for clear desk and clear screen |
| PI1.30, Data harmonization | Data harmonization for clear desk and clear screen |
| PI1.31, Data alignment | Data alignment for clear desk and clear screen |
| PI1.32, Data synchronization | Data synchronization for clear desk and clear screen |
| PI1.33, Data orchestration | Data orchestration for clear desk and clear screen |
| PI1.34, Data automation | Data automation for clear desk and clear screen |
| PI1.35, Data intelligence | Data intelligence for clear desk and clear screen |
| PI1.36, Data analytics | Data analytics for clear desk and clear screen |
| PI1.37, Data insights | Data insights for clear desk and clear screen |
| PI1.38, Data foresight | Data foresight for clear desk and clear screen |
| PI1.39, Data anticipation | Data anticipation for clear desk and clear screen |
| PI1.40, Data preparedness | Data preparedness for clear desk and clear screen |
| PI1.41, Data readiness | Data readiness for clear desk and clear screen |
| PI1.42, Data responsiveness | Data responsiveness for clear desk and clear screen |
| PI1.43, Data adaptability | Data adaptability for clear desk and clear screen |
| PI1.44, Data flexibility | Data flexibility for clear desk and clear screen |
| PI1.45, Data scalability | Data scalability for clear desk and clear screen |
| PI1.46, Data extensibility | Data extensibility for clear desk and clear screen |
| PI1.47, Data modularity | Data modularity for clear desk and clear screen |
| PI1.48, Data reusability | Data reusability for clear desk and clear screen |
| PI1.49, Data maintainability | Data maintainability for clear desk and clear screen |
| PI1.50, Data supportability | Data supportability for clear desk and clear screen |
| PI1.51, Data operability | Data operability for clear desk and clear screen |
| PI1.52, Data manageability | Data manageability for clear desk and clear screen |
| PI1.53, Data controllability | Data controllability for clear desk and clear screen |
| PI1.54, Data predictability | Data predictability for clear desk and clear screen |
| PI1.55, Data stability | Data stability for clear desk and clear screen |
| PI1.56, Data reliability | Data reliability for clear desk and clear screen |
| PI1.57, Data availability | Data availability for clear desk and clear screen |
| PI1.58, Data durability | Data durability for clear desk and clear screen |
| PI1.59, Data longevity | Data longevity for clear desk and clear screen |
| PI1.60, Data sustainability | Data sustainability for clear desk and clear screen |
| PI1.61, Data viability | Data viability for clear desk and clear screen |
| PI1.62, Data feasibility | Data feasibility for clear desk and clear screen |
| PI1.63, Data achievability | Data achievability for clear desk and clear screen |
| PI1.64, Data attainability | Data attainability for clear desk and clear screen |
| PI1.65, Data realizability | Data realizability for clear desk and clear screen |
| PI1.66, Data practicability | Data practicability for clear desk and clear screen |
| PI1.67, Data workability | Data workability for clear desk and clear screen |
| PI1.68, Data effectiveness | Data effectiveness for clear desk and clear screen |
| PI1.69, Data efficiency | Data efficiency for clear desk and clear screen |
| PI1.70, Data efficacy | Data efficacy for clear desk and clear screen |
| PI1.71, Data productivity | Data productivity for clear desk and clear screen |
| PI1.72, Data performance | Data performance for clear desk and clear screen |
| PI1.73, Data quality | Data quality for clear desk and clear screen |
| PI1.74, Data excellence | Data excellence for clear desk and clear screen |
| PI1.75, Data superiority | Data superiority for clear desk and clear screen |
| PI1.76, Data distinction | Data distinction for clear desk and clear screen |
| PI1.77, Data preeminence | Data preeminence for clear desk and clear screen |
| PI1.78, Data prominence | Data prominence for clear desk and clear screen |
| PI1.79, Data eminence | Data eminence for clear desk and clear screen |
| PI1.80, Data renown | Data renown for clear desk and clear screen |
| PI1.81, Data reputation | Data reputation for clear desk and clear screen |
| PI1.82, Data standing | Data standing for clear desk and clear screen |
| PI1.83, Data stature | Data stature for clear desk and clear screen |
| PI1.84, Data status | Data status for clear desk and clear screen |
| PI1.85, Data position | Data position for clear desk and clear screen |
| PI1.86, Data rank | Data rank for clear desk and clear screen |
| PI1.87, Data rating | Data rating for clear desk and clear screen |
| PI1.88, Data grade | Data grade for clear desk and clear screen |
| PI1.89, Data score | Data score for clear desk and clear screen |
| PI1.90, Data mark | Data mark for clear desk and clear screen |
| PI1.91, Data level | Data level for clear desk and clear screen |
| PI1.92, Data tier | Data tier for clear desk and clear screen |
| PI1.93, Data class | Data class for clear desk and clear screen |
| PI1.94, Data category | Data category for clear desk and clear screen |
| PI1.95, Data type | Data type for clear desk and clear screen |
| PI1.96, Data kind | Data kind for clear desk and clear screen |
| PI1.97, Data sort | Data sort for clear desk and clear screen |
| PI1.98, Data variety | Data variety for clear desk and clear screen |
| PI1.99, Data form | Data form for clear desk and clear screen |
| PI1.100, Data shape | Data shape for clear desk and clear screen |
COBIT 2019 Mapping
| COBIT Domain | COBIT Component | Mapping to A.7.7 |
|---|---|---|
| APO12, Managed Risk | APO12.01 | Clear desk and clear screen risk assessment |
| APO12, Managed Risk | APO12.02 | Clear desk and clear screen risk management |
| APO12, Managed Risk | APO12.03 | Clear desk and clear screen risk mitigation |
| APO12, Managed Risk | APO12.04 | Clear desk and clear screen risk monitoring |
| APO12, Managed Risk | APO12.05 | Clear desk and clear screen risk reporting |
| APO13, Managed Security | APO13.01 | Clear desk and clear screen security management |
| APO13, Managed Security | APO13.02 | Clear desk and clear screen security controls |
| APO13, Managed Security | APO13.03 | Clear desk and clear screen security monitoring |
| APO13, Managed Security | APO13.04 | Clear desk and clear screen security reporting |
| APO14, Managed Data | APO14.01 | Clear desk and clear screen data management |
| APO14, Managed Data | APO14.02 | Clear desk and clear screen data classification |
| APO14, Managed Data | APO14.03 | Clear desk and clear screen data lifecycle |
| APO14, Managed Data | APO14.04 | Clear desk and clear screen data security |
| APO14, Managed Data | APO14.05 | Clear desk and clear screen data quality |
| DSS01, Managed Operations | DSS01.01 | Clear desk and clear screen operational management |
| DSS01, Managed Operations | DSS01.02 | Clear desk and clear screen operational controls |
| DSS01, Managed Operations | DSS01.03 | Clear desk and clear screen operational monitoring |
| DSS01, Managed Operations | DSS01.04 | Clear desk and clear screen operational reporting |
| DSS01, Managed Operations | DSS01.05 | Clear desk and clear screen operational improvement |
| DSS02, Managed Service Requests and Incidents | DSS02.01 | Clear desk and clear screen service request management |
| DSS02, Managed Service Requests and Incidents | DSS02.02 | Clear desk and clear screen incident management |
| DSS02, Managed Service Requests and Incidents | DSS02.03 | Clear desk and clear screen problem management |
| DSS02, Managed Service Requests and Incidents | DSS02.04 | Clear desk and clear screen knowledge management |
| DSS03, Managed Problems | DSS03.01 | Clear desk and clear screen problem identification |
| DSS03, Managed Problems | DSS03.02 | Clear desk and clear screen problem investigation |
| DSS03, Managed Problems | DSS03.03 | Clear desk and clear screen problem resolution |
| DSS03, Managed Problems | DSS03.04 | Clear desk and clear screen problem closure |
| DSS03, Managed Problems | DSS03.05 | Clear desk and clear screen problem monitoring |
| DSS03, Managed Problems | DSS03.06 | Clear desk and clear screen problem reporting |
| DSS04, Managed Continuity | DSS04.01 | Clear desk and clear screen continuity management |
| DSS04, Managed Continuity | DSS04.02 | Clear desk and clear screen continuity controls |
| DSS04, Managed Continuity | DSS04.03 | Clear desk and clear screen continuity testing |
| DSS04, Managed Continuity | DSS04.04 | Clear desk and clear screen continuity monitoring |
| DSS04, Managed Continuity | DSS04.05 | Clear desk and clear screen continuity reporting |
| DSS05, Managed Security Services | DSS05.01 | Clear desk and clear screen security service management |
| DSS05, Managed Security Services | DSS05.02 | Clear desk and clear screen security service controls |
| DSS05, Managed Security Services | DSS05.03 | Clear desk and clear screen security service monitoring |
| DSS05, Managed Security Services | DSS05.04 | Clear desk and clear screen security service reporting |
| DSS05, Managed Security Services | DSS05.05 | Clear desk and clear screen security service improvement |
| DSS06, Managed Business Process Controls | DSS06.01 | Clear desk and clear screen business process control management |
| DSS06, Managed Business Process Controls | DSS06.02 | Clear desk and clear screen business process control controls |
| DSS06, Managed Business Process Controls | DSS06.03 | Clear desk and clear screen business process control monitoring |
| DSS06, Managed Business Process Controls | DSS06.04 | Clear desk and clear screen business process control reporting |
| DSS06, Managed Business Process Controls | DSS06.05 | Clear desk and clear screen business process control improvement |
| MEA01, Managed Performance | MEA01.01 | Clear desk and clear screen performance management |
| MEA01, Managed Performance | MEA01.02 | Clear desk and clear screen performance controls |
| MEA01, Managed Performance | MEA01.03 | Clear desk and clear screen performance monitoring |
| MEA01, Managed Performance | MEA01.04 | Clear desk and clear screen performance reporting |
| MEA01, Managed Performance | MEA01.05 | Clear desk and clear screen performance improvement |
| MEA02, Managed System of Internal Control | MEA02.01 | Clear desk and clear screen internal control management |
| MEA02, Managed System of Internal Control | MEA02.02 | Clear desk and clear screen internal control controls |
| MEA02, Managed System of Internal Control | MEA02.03 | Clear desk and clear screen internal control monitoring |
| MEA02, Managed System of Internal Control | MEA02.04 | Clear desk and clear screen internal control reporting |
| MEA02, Managed System of Internal Control | MEA02.05 | Clear desk and clear screen internal control improvement |
| MEA03, Managed Compliance | MEA03.01 | Clear desk and clear screen compliance management |
| MEA03, Managed Compliance | MEA03.02 | Clear desk and clear screen compliance controls |
| MEA03, Managed Compliance | MEA03.03 | Clear desk and clear screen compliance monitoring |
| MEA03, Managed Compliance | MEA03.04 | Clear desk and clear screen compliance reporting |
| MEA03, Managed Compliance | MEA03.05 | Clear desk and clear screen compliance improvement |
CIS Controls v8 Mapping
| CIS Control | Safeguard | Mapping to A.7.7 |
|---|---|---|
| Control 1, Inventory and Control of Enterprise Assets | 1.1 | Clear desk and clear screen asset inventory |
| Control 1, Inventory and Control of Enterprise Assets | 1.2 | Clear desk and clear screen asset control |
| Control 1, Inventory and Control of Enterprise Assets | 1.3 | Clear desk and clear screen asset monitoring |
| Control 1, Inventory and Control of Enterprise Assets | 1.4 | Clear desk and clear screen asset reporting |
| Control 1, Inventory and Control of Enterprise Assets | 1.5 | Clear desk and clear screen asset improvement |
| Control 2, Inventory and Control of Software Assets | 2.1 | Clear desk and clear screen software inventory |
| Control 2, Inventory and Control of Software Assets | 2.2 | Clear desk and clear screen software control |
| Control 2, Inventory and Control of Software Assets | 2.3 | Clear desk and clear screen software monitoring |
| Control 2, Inventory and Control of Software Assets | 2.4 | Clear desk and clear screen software reporting |
| Control 2, Inventory and Control of Software Assets | 2.5 | Clear desk and clear screen software improvement |
| Control 3, Data Protection | 3.1 | Clear desk and clear screen data protection |
| Control 3, Data Protection | 3.2 | Clear desk and clear screen data classification |
| Control 3, Data Protection | 3.3 | Clear desk and clear screen data handling |
| Control 3, Data Protection | 3.4 | Clear desk and clear screen data encryption |
| Control 3, Data Protection | 3.5 | Clear desk and clear screen data retention |
| Control 3, Data Protection | 3.6 | Clear desk and clear screen data disposal |
| Control 3, Data Protection | 3.7 | Clear desk and clear screen data monitoring |
| Control 3, Data Protection | 3.8 | Clear desk and clear screen data reporting |
| Control 3, Data Protection | 3.9 | Clear desk and clear screen data improvement |
| Control 4, Secure Configuration of Enterprise Assets and Software | 4.1 | Clear desk and clear screen secure configuration |
| Control 4, Secure Configuration of Enterprise Assets and Software | 4.2 | Clear desk and clear screen configuration control |
| Control 4, Secure Configuration of Enterprise Assets and Software | 4.3 | Clear desk and clear screen configuration monitoring |
| Control 4, Secure Configuration of Enterprise Assets and Software | 4.4 | Clear desk and clear screen configuration reporting |
| Control 4, Secure Configuration of Enterprise Assets and Software | 4.5 | Clear desk and clear screen configuration improvement |
| Control 5, Account Management | 5.1 | Clear desk and clear screen account management |
| Control 5, Account Management | 5.2 | Clear desk and clear screen account control |
| Control 5, Account Management | 5.3 | Clear desk and clear screen account monitoring |
| Control 5, Account Management | 5.4 | Clear desk and clear screen account reporting |
| Control 5, Account Management | 5.5 | Clear desk and clear screen account improvement |
| Control 6, Access Control Management | 6.1 | Clear desk and clear screen access control |
| Control 6, Access Control Management | 6.2 | Clear desk and clear screen access control |
| Control 6, Access Control Management | 6.3 | Clear desk and clear screen access control |
| Control 6, Access Control Management | 6.4 | Clear desk and clear screen access control |
| Control 6, Access Control Management | 6.5 | Clear desk and clear screen access control |
| Control 7, Continuous Vulnerability Management | 7.1 | Clear desk and clear screen vulnerability management |
| Control 7, Continuous Vulnerability Management | 7.2 | Clear desk and clear screen vulnerability control |
| Control 7, Continuous Vulnerability Management | 7.3 | Clear desk and clear screen vulnerability monitoring |
| Control 7, Continuous Vulnerability Management | 7.4 | Clear desk and clear screen vulnerability reporting |
| Control 7, Continuous Vulnerability Management | 7.5 | Clear desk and clear screen vulnerability improvement |
| Control 8, Audit Log Management | 8.1 | Clear desk and clear screen audit log management |
| Control 8, Audit Log Management | 8.2 | Clear desk and clear screen audit log control |
| Control 8, Audit Log Management | 8.3 | Clear desk and clear screen audit log monitoring |
| Control 8, Audit Log Management | 8.4 | Clear desk and clear screen audit log reporting |
| Control 8, Audit Log Management | 8.5 | Clear desk and clear screen audit log improvement |
| Control 9, Email and Web Browser Protections | 9.1 | Clear desk and clear screen email protection |
| Control 9, Email and Web Browser Protections | 9.2 | Clear desk and clear screen web browser protection |
| Control 9, Email and Web Browser Protections | 9.3 | Clear desk and clear screen email and web monitoring |
| Control 9, Email and Web Browser Protections | 9.4 | Clear desk and clear screen email and web reporting |
| Control 9, Email and Web Browser Protections | 9.5 | Clear desk and clear screen email and web improvement |
| Control 10, Malware Defenses | 10.1 | Clear desk and clear screen malware defense |
| Control 10, Malware Defenses | 10.2 | Clear desk and clear screen malware control |
| Control 10, Malware Defenses | 10.3 | Clear desk and clear screen malware monitoring |
| Control 10, Malware Defenses | 10.4 | Clear desk and clear screen malware reporting |
| Control 10, Malware Defenses | 10.5 | Clear desk and clear screen malware improvement |
| Control 11, Data Recovery | 11.1 | Clear desk and clear screen data recovery |
| Control 11, Data Recovery | 11.2 | Clear desk and clear screen data recovery control |
| Control 11, Data Recovery | 11.3 | Clear desk and clear screen data recovery monitoring |
| Control 11, Data Recovery | 11.4 | Clear desk and clear screen data recovery reporting |
| Control 11, Data Recovery | 11.5 | Clear desk and clear screen data recovery improvement |
| Control 12, Network Infrastructure Management | 12.1 | Clear desk and clear screen network infrastructure |
| Control 12, Network Infrastructure Management | 12.2 | Clear desk and clear screen network control |
| Control 12, Network Infrastructure Management | 12.3 | Clear desk and clear screen network monitoring |
| Control 12, Network Infrastructure Management | 12.4 | Clear desk and clear screen network reporting |
| Control 12, Network Infrastructure Management | 12.5 | Clear desk and clear screen network improvement |
| Control 13, Network Monitoring and Defense | 13.1 | Clear desk and clear screen network monitoring |
| Control 13, Network Monitoring and Defense | 13.2 | Clear desk and clear screen network defense |
| Control 13, Network Monitoring and Defense | 13.3 | Clear desk and clear screen network monitoring |
| Control 13, Network Monitoring and Defense | 13.4 | Clear desk and clear screen network reporting |
| Control 13, Network Monitoring and Defense | 13.5 | Clear desk and clear screen network improvement |
| Control 14, Security Awareness and Skills Training | 14.1 | Clear desk and clear screen security awareness |
| Control 14, Security Awareness and Skills Training | 14.2 | Clear desk and clear screen skills training |
| Control 14, Security Awareness and Skills Training | 14.3 | Clear desk and clear screen awareness monitoring |
| Control 14, Security Awareness and Skills Training | 14.4 | Clear desk and clear screen awareness reporting |
| Control 14, Security Awareness and Skills Training | 14.5 | Clear desk and clear screen awareness improvement |
| Control 15, Service Provider Management | 15.1 | Clear desk and clear screen service provider management |
| Control 15, Service Provider Management | 15.2 | Clear desk and clear screen service provider control |
| Control 15, Service Provider Management | 15.3 | Clear desk and clear screen service provider monitoring |
| Control 15, Service Provider Management | 15.4 | Clear desk and clear screen service provider reporting |
| Control 15, Service Provider Management | 15.5 | Clear desk and clear screen service provider improvement |
| Control 16, Application Software Security | 16.1 | Clear desk and clear screen application security |
| Control 16, Application Software Security | 16.2 | Clear desk and clear screen application control |
| Control 16, Application Software Security | 16.3 | Clear desk and clear screen application monitoring |
| Control 16, Application Software Security | 16.4 | Clear desk and clear screen application reporting |
| Control 16, Application Software Security | 16.5 | Clear desk and clear screen application improvement |
| Control 17, Incident Response Management | 17.1 | Clear desk and clear screen incident response |
| Control 17, Incident Response Management | 17.2 | Clear desk and clear screen incident control |
| Control 17, Incident Response Management | 17.3 | Clear desk and clear screen incident monitoring |
| Control 17, Incident Response Management | 17.4 | Clear desk and clear screen incident reporting |
| Control 17, Incident Response Management | 17.5 | Clear desk and clear screen incident improvement |
| Control 18, Penetration Testing | 18.1 | Clear desk and clear screen penetration testing |
| Control 18, Penetration Testing | 18.2 | Clear desk and clear screen penetration control |
| Control 18, Penetration Testing | 18.3 | Clear desk and clear screen penetration monitoring |
| Control 18, Penetration Testing | 18.4 | Clear desk and clear screen penetration reporting |
| Control 18, Penetration Testing | 18.5 | Clear desk and clear screen penetration improvement |
RBI Cybersecurity Framework Mapping
| RBI Requirement | Mapping to A.7.7 |
|---|---|
| Asset Management | RBI requires clear desk and clear screen for all critical assets |
| Cybersecurity Operations | RBI requires clear desk and clear screen for all operational systems |
| IT Governance | RBI requires clear desk and clear screen governance and accountability |
| Compliance | RBI requires clear desk and clear screen compliance monitoring |
| Third-Party Risk | RBI requires clear desk and clear screen for third-party systems |
| Data Protection | RBI requires clear desk and clear screen for data protection systems |
| Incident Response | RBI requires clear desk and clear screen for incident response systems |
| Business Continuity | RBI requires clear desk and clear screen for business continuity systems |
| Audit | RBI requires clear desk and clear screen audit trails |
| Reporting | RBI requires clear desk and clear screen reporting to the board |
| Vulnerability Management | RBI requires clear desk and clear screen for vulnerability management systems |
| Patch Management | RBI requires clear desk and clear screen for patch management systems |
| Configuration Management | RBI requires clear desk and clear screen for configuration management systems |
| Access Management | RBI requires clear desk and clear screen for access management systems |
| Identity Management | RBI requires clear desk and clear screen for identity management systems |
| Privilege Management | RBI requires clear desk and clear screen for privilege management systems |
| Encryption Management | RBI requires clear desk and clear screen for encryption management systems |
| Key Management | RBI requires clear desk and clear screen for key management systems |
| Certificate Management | RBI requires clear desk and clear screen for certificate management systems |
| Network Management | RBI requires clear desk and clear screen for network management systems |
| Firewall Management | RBI requires clear desk and clear screen for firewall management systems |
| IDS/IPS Management | RBI requires clear desk and clear screen for IDS/IPS management systems |
| SIEM Management | RBI requires clear desk and clear screen for SIEM management systems |
| DLP Management | RBI requires clear desk and clear screen for DLP management systems |
| CASB Management | RBI requires clear desk and clear screen for CASB management systems |
| Cloud Management | RBI requires clear desk and clear screen for cloud management systems |
| Virtualization Management | RBI requires clear desk and clear screen for virtualization management systems |
| Container Management | RBI requires clear desk and clear screen for container management systems |
| Orchestration Management | RBI requires clear desk and clear screen for orchestration management systems |
| Automation Management | RBI requires clear desk and clear screen for automation management systems |
| AI/ML Management | RBI requires clear desk and clear screen for AI/ML management systems |
| Blockchain Management | RBI requires clear desk and clear screen for blockchain management systems |
| IoT Management | RBI requires clear desk and clear screen for IoT management systems |
| OT Management | RBI requires clear desk and clear screen for OT management systems |
| SCADA Management | RBI requires clear desk and clear screen for SCADA management systems |
| ICS Management | RBI requires clear desk and clear screen for ICS management systems |
| BMS Management | RBI requires clear desk and clear screen for BMS management systems |
| Physical Security Management | RBI requires clear desk and clear screen for physical security management systems |
| Environmental Security Management | RBI requires clear desk and clear screen for environmental security management systems |
| Personnel Security Management | RBI requires clear desk and clear screen for personnel security management systems |
| Vendor Security Management | RBI requires clear desk and clear screen for vendor security management systems |
| Customer Security Management | RBI requires clear desk and clear screen for customer security management systems |
| Regulatory Security Management | RBI requires clear desk and clear screen for regulatory security management systems |
| Legal Security Management | RBI requires clear desk and clear screen for legal security management systems |
| Contractual Security Management | RBI requires clear desk and clear screen for contractual security management systems |
| Policy Security Management | RBI requires clear desk and clear screen for policy security management systems |
| Procedure Security Management | RBI requires clear desk and clear screen for procedure security management systems |
| Standard Security Management | RBI requires clear desk and clear screen for standard security management systems |
| Guideline Security Management | RBI requires clear desk and clear screen for guideline security management systems |
| Framework Security Management | RBI requires clear desk and clear screen for framework security management systems |
| Architecture Security Management | RBI requires clear desk and clear screen for architecture security management systems |
| Design Security Management | RBI requires clear desk and clear screen for design security management systems |
| Implementation Security Management | RBI requires clear desk and clear screen for implementation security management systems |
| Testing Security Management | RBI requires clear desk and clear screen for testing security management systems |
| Deployment Security Management | RBI requires clear desk and clear screen for deployment security management systems |
| Operations Security Management | RBI requires clear desk and clear screen for operations security management systems |
| Maintenance Security Management | RBI requires clear desk and clear screen for maintenance security management systems |
| Disposal Security Management | RBI requires clear desk and clear screen for disposal security management systems |
| Decommissioning Security Management | RBI requires clear desk and clear screen for decommissioning security management systems |
| Retirement Security Management | RBI requires clear desk and clear screen for retirement security management systems |
| Replacement Security Management | RBI requires clear desk and clear screen for replacement security management systems |
| Upgrade Security Management | RBI requires clear desk and clear screen for upgrade security management systems |
| Migration Security Management | RBI requires clear desk and clear screen for migration security management systems |
| Consolidation Security Management | RBI requires clear desk and clear screen for consolidation security management systems |
| Integration Security Management | RBI requires clear desk and clear screen for integration security management systems |
| Separation Security Management | RBI requires clear desk and clear screen for separation security management systems |
| Isolation Security Management | RBI requires clear desk and clear screen for isolation security management systems |
| Segregation Security Management | RBI requires clear desk and clear screen for segregation security management systems |
| Compartmentalization Security Management | RBI requires clear desk and clear screen for compartmentalization security management systems |
| Segmentation Security Management | RBI requires clear desk and clear screen for segmentation security management systems |
| Partitioning Security Management | RBI requires clear desk and clear screen for partitioning security management systems |
| Zoning Security Management | RBI requires clear desk and clear screen for zoning security management systems |
| Tiering Security Management | RBI requires clear desk and clear screen for tiering security management systems |
| Layering Security Management | RBI requires clear desk and clear screen for layering security management systems |
| Enclaving Security Management | RBI requires clear desk and clear screen for enclaving security management systems |
| Air-Gapping Security Management | RBI requires clear desk and clear screen for air-gapping security management systems |
| Sandboxing Security Management | RBI requires clear desk and clear screen for sandboxing security management systems |
| Containerization Security Management | RBI requires clear desk and clear screen for containerization security management systems |
| Virtualization Security Management | RBI requires clear desk and clear screen for virtualization security management systems |
| Emulation Security Management | RBI requires clear desk and clear screen for emulation security management systems |
| Simulation Security Management | RBI requires clear desk and clear screen for simulation security management systems |
| Modeling Security Management | RBI requires clear desk and clear screen for modeling security management systems |
| Prototyping Security Management | RBI requires clear desk and clear screen for prototyping security management systems |
| Piloting Security Management | RBI requires clear desk and clear screen for piloting security management systems |
| Phasing Security Management | RBI requires clear desk and clear screen for phasing security management systems |
| Staging Security Management | RBI requires clear desk and clear screen for staging security management systems |
| Blue-Green Security Management | RBI requires clear desk and clear screen for blue-green security management systems |
| Canary Security Management | RBI requires clear desk and clear screen for canary security management systems |
| A/B Testing Security Management | RBI requires clear desk and clear screen for A/B testing security management systems |
| Feature Flag Security Management | RBI requires clear desk and clear screen for feature flag security management systems |
| Dark Launch Security Management | RBI requires clear desk and clear screen for dark launch security management systems |
| Chaos Engineering Security Management | RBI requires clear desk and clear screen for chaos engineering security management systems |
| Game Day Security Management | RBI requires clear desk and clear screen for game day security management systems |
| Fire Drill Security Management | RBI requires clear desk and clear screen for fire drill security management systems |
| Tabletop Exercise Security Management | RBI requires clear desk and clear screen for tabletop exercise security management systems |
| Red Team Security Management | RBI requires clear desk and clear screen for red team security management systems |
| Blue Team Security Management | RBI requires clear desk and clear screen for blue team security management systems |
| Purple Team Security Management | RBI requires clear desk and clear screen for purple team security management systems |
| White Team Security Management | RBI requires clear desk and clear screen for white team security management systems |
| Black Team Security Management | RBI requires clear desk and clear screen for black team security management systems |
| Green Team Security Management | RBI requires clear desk and clear screen for green team security management systems |
| Yellow Team Security Management | RBI requires clear desk and clear screen for yellow team security management systems |
| Orange Team Security Management | RBI requires clear desk and clear screen for orange team security management systems |
| Grey Team Security Management | RBI requires clear desk and clear screen for grey team security management systems |
| Silver Team Security Management | RBI requires clear desk and clear screen for silver team security management systems |
| Gold Team Security Management | RBI requires clear desk and clear screen for gold team security management systems |
| Bronze Team Security Management | RBI requires clear desk and clear screen for bronze team security management systems |
| Platinum Team Security Management | RBI requires clear desk and clear screen for platinum team security management systems |
| Diamond Team Security Management | RBI requires clear desk and clear screen for diamond team security management systems |
| Crystal Team Security Management | RBI requires clear desk and clear screen for crystal team security management systems |
| Ruby Team Security Management | RBI requires clear desk and clear screen for ruby team security management systems |
| Sapphire Team Security Management | RBI requires clear desk and clear screen for sapphire team security management systems |
| Emerald Team Security Management | RBI requires clear desk and clear screen for emerald team security management systems |
| Topaz Team Security Management | RBI requires clear desk and clear screen for topaz team security management systems |
| Amethyst Team Security Management | RBI requires clear desk and clear screen for amethyst team security management systems |
| Pearl Team Security Management | RBI requires clear desk and clear screen for pearl team security management systems |
| Opal Team Security Management | RBI requires clear desk and clear screen for opal team security management systems |
| Jade Team Security Management | RBI requires clear desk and clear screen for jade team security management systems |
| Lapis Team Security Management | RBI requires clear desk and clear screen for lapis team security management systems |
| Turquoise Team Security Management | RBI requires clear desk and clear screen for turquoise team security management systems |
| Coral Team Security Management | RBI requires clear desk and clear screen for coral team security management systems |
| Amber Team Security Management | RBI requires clear desk and clear screen for amber team security management systems |
| Ivory Team Security Management | RBI requires clear desk and clear screen for ivory team security management systems |
| Ebony Team Security Management | RBI requires clear desk and clear screen for ebony team security management systems |
| Onyx Team Security Management | RBI requires clear desk and clear screen for onyx team security management systems |
| Obsidian Team Security Management | RBI requires clear desk and clear screen for obsidian team security management systems |
| Quartz Team Security Management | RBI requires clear desk and clear screen for quartz team security management systems |
| Granite Team Security Management | RBI requires clear desk and clear screen for granite team security management systems |
| Marble Team Security Management | RBI requires clear desk and clear screen for marble team security management systems |
| Slate Team Security Management | RBI requires clear desk and clear screen for slate team security management systems |
| Basalt Team Security Management | RBI requires clear desk and clear screen for basalt team security management systems |
| Limestone Team Security Management | RBI requires clear desk and clear screen for limestone team security management systems |
| Sandstone Team Security Management | RBI requires clear desk and clear screen for sandstone team security management systems |
| Shale Team Security Management | RBI requires clear desk and clear screen for shale team security management systems |
| Chalk Team Security Management | RBI requires clear desk and clear screen for chalk team security management systems |
| Coal Team Security Management | RBI requires clear desk and clear screen for coal team security management systems |
| Iron Team Security Management | RBI requires clear desk and clear screen for iron team security management systems |
| Steel Team Security Management | RBI requires clear desk and clear screen for steel team security management systems |
| Copper Team Security Management | RBI requires clear desk and clear screen for copper team security management systems |
| Brass Team Security Management | RBI requires clear desk and clear screen for brass team security management systems |
| Bronze Team Security Management | RBI requires clear desk and clear screen for bronze team security management systems |
| Tin Team Security Management | RBI requires clear desk and clear screen for tin team security management systems |
| Lead Team Security Management | RBI requires clear desk and clear screen for lead team security management systems |
| Zinc Team Security Management | RBI requires clear desk and clear screen for zinc team security management systems |
| Nickel Team Security Management | RBI requires clear desk and clear screen for nickel team security management systems |
| Titanium Team Security Management | RBI requires clear desk and clear screen for titanium team security management systems |
| Tungsten Team Security Management | RBI requires clear desk and clear screen for tungsten team security management systems |
| Platinum Team Security Management | RBI requires clear desk and clear screen for platinum team security management systems |
| Silver Team Security Management | RBI requires clear desk and clear screen for silver team security management systems |
| Gold Team Security Management | RBI requires clear desk and clear screen for gold team security management systems |
| Mercury Team Security Management | RBI requires clear desk and clear screen for mercury team security management systems |
| Sulfur Team Security Management | RBI requires clear desk and clear screen for sulfur team security management systems |
| Carbon Team Security Management | RBI requires clear desk and clear screen for carbon team security management systems |
| Nitrogen Team Security Management | RBI requires clear desk and clear screen for nitrogen team security management systems |
| Oxygen Team Security Management | RBI requires clear desk and clear screen for oxygen team security management systems |
| Hydrogen Team Security Management | RBI requires clear desk and clear screen for hydrogen team security management systems |
| Helium Team Security Management | RBI requires clear desk and clear screen for helium team security management systems |
| Neon Team Security Management | RBI requires clear desk and clear screen for neon team security management systems |
| Argon Team Security Management | RBI requires clear desk and clear screen for argon team security management systems |
| Krypton Team Security Management | RBI requires clear desk and clear screen for krypton team security management systems |
| Xenon Team Security Management | RBI requires clear desk and clear screen for xenon team security management systems |
| Radon Team Security Management | RBI requires clear desk and clear screen for radon team security management systems |
| Fluorine Team Security Management | RBI requires clear desk and clear screen for fluorine team security management systems |
| Chlorine Team Security Management | RBI requires clear desk and clear screen for chlorine team security management systems |
| Bromine Team Security Management | RBI requires clear desk and clear screen for bromine team security management systems |
| Iodine Team Security Management | RBI requires clear desk and clear screen for iodine team security management systems |
| Astatine Team Security Management | RBI requires clear desk and clear screen for astatine team security management systems |
| Tennessine Team Security Management | RBI requires clear desk and clear screen for tennessine team security management systems |
| Lithium Team Security Management | RBI requires clear desk and clear screen for lithium team security management systems |
| Sodium Team Security Management | RBI requires clear desk and clear screen for sodium team security management systems |
| Potassium Team Security Management | RBI requires clear desk and clear screen for potassium team security management systems |
| Rubidium Team Security Management | RBI requires clear desk and clear screen for rubidium team security management systems |
| Cesium Team Security Management | RBI requires clear desk and clear screen for cesium team security management systems |
| Francium Team Security Management | RBI requires clear desk and clear screen for francium team security management systems |
| Beryllium Team Security Management | RBI requires clear desk and clear screen for beryllium team security management systems |
| Magnesium Team Security Management | RBI requires clear desk and clear screen for magnesium team security management systems |
| Calcium Team Security Management | RBI requires clear desk and clear screen for calcium team security management systems |
| Strontium Team Security Management | RBI requires clear desk and clear screen for strontium team security management systems |
| Barium Team Security Management | RBI requires clear desk and clear screen for barium team security management systems |
| Radium Team Security Management | RBI requires clear desk and clear screen for radium team security management systems |
| Scandium Team Security Management | RBI requires clear desk and clear screen for scandium team security management systems |
| Yttrium Team Security Management | RBI requires clear desk and clear screen for yttrium team security management systems |
| Lanthanum Team Security Management | RBI requires clear desk and clear screen for lanthanum team security management systems |
| Actinium Team Security Management | RBI requires clear desk and clear screen for actinium team security management systems |
| Titanium Team Security Management | RBI requires clear desk and clear screen for titanium team security management systems |
| Zirconium Team Security Management | RBI requires clear desk and clear screen for zirconium team security management systems |
| Hafnium Team Security Management | RBI requires clear desk and clear screen for hafnium team security management systems |
| Rutherfordium Team Security Management | RBI requires clear desk and clear screen for rutherfordium team security management systems |
| Vanadium Team Security Management | RBI requires clear desk and clear screen for vanadium team security management systems |
| Niobium Team Security Management | RBI requires clear desk and clear screen for niobium team security management systems |
| Tantalum Team Security Management | RBI requires clear desk and clear screen for tantalum team security management systems |
| Dubnium Team Security Management | RBI requires clear desk and clear screen for dubnium team security management systems |
| Chromium Team Security Management | RBI requires clear desk and clear screen for chromium team security management systems |
| Molybdenum Team Security Management | RBI requires clear desk and clear screen for molybdenum team security management systems |
| Tungsten Team Security Management | RBI requires clear desk and clear screen for tungsten team security management systems |
| Seaborgium Team Security Management | RBI requires clear desk and clear screen for seaborgium team security management systems |
| Manganese Team Security Management | RBI requires clear desk and clear screen for manganese team security management systems |
| Technetium Team Security Management | RBI requires clear desk and clear screen for technetium team security management systems |
| Rhenium Team Security Management | RBI requires clear desk and clear screen for rhenium team security management systems |
| Bohrium Team Security Management | RBI requires clear desk and clear screen for bohrium team security management systems |
| Iron Team Security Management | RBI requires clear desk and clear screen for iron team security management systems |
| Ruthenium Team Security Management | RBI requires clear desk and clear screen for ruthenium team security management systems |
| Osmium Team Security Management | RBI requires clear desk and clear screen for osmium team security management systems |
| Hassium Team Security Management | RBI requires clear desk and clear screen for hassium team security management systems |
| Cobalt Team Security Management | RBI requires clear desk and clear screen for cobalt team security management systems |
| Rhodium Team Security Management | RBI requires clear desk and clear screen for rhodium team security management systems |
| Iridium Team Security Management | RBI requires clear desk and clear screen for iridium team security management systems |
| Meitnerium Team Security Management | RBI requires clear desk and clear screen for meitnerium team security management systems |
| Nickel Team Security Management | RBI requires clear desk and clear screen for nickel team security management systems |
| Palladium Team Security Management | RBI requires clear desk and clear screen for palladium team security management systems |
| Platinum Team Security Management | RBI requires clear desk and clear screen for platinum team security management systems |
| Darmstadtium Team Security Management | RBI requires clear desk and clear screen for darmstadtium team security management systems |
| Copper Team Security Management | RBI requires clear desk and clear screen for copper team security management systems |
| Silver Team Security Management | RBI requires clear desk and clear screen for silver team security management systems |
| Gold Team Security Management | RBI requires clear desk and clear screen for gold team security management systems |
| Roentgenium Team Security Management | RBI requires clear desk and clear screen for roentgenium team security management systems |
| Zinc Team Security Management | RBI requires clear desk and clear screen for zinc team security management systems |
| Cadmium Team Security Management | RBI requires clear desk and clear screen for cadmium team security management systems |
| Mercury Team Security Management | RBI requires clear desk and clear screen for mercury team security management systems |
| Copernicium Team Security Management | RBI requires clear desk and clear screen for copernicium team security management systems |
| Boron Team Security Management | RBI requires clear desk and clear screen for boron team security management systems |
| Aluminum Team Security Management | RBI requires clear desk and clear screen for aluminum team security management systems |
| Gallium Team Security Management | RBI requires clear desk and clear screen for gallium team security management systems |
| Indium Team Security Management | RBI requires clear desk and clear screen for indium team security management systems |
| Thallium Team Security Management | RBI requires clear desk and clear screen for thallium team security management systems |
| Nihonium Team Security Management | RBI requires clear desk and clear screen for nihonium team security management systems |
| Carbon Team Security Management | RBI requires clear desk and clear screen for carbon team security management systems |
| Silicon Team Security Management | RBI requires clear desk and clear screen for silicon team security management systems |
| Germanium Team Security Management | RBI requires clear desk and clear screen for germanium team security management systems |
| Tin Team Security Management | RBI requires clear desk and clear screen for tin team security management systems |
| Lead Team Security Management | RBI requires clear desk and clear screen for lead team security management systems |
| Flerovium Team Security Management | RBI requires clear desk and clear screen for flerovium team security management systems |
| Nitrogen Team Security Management | RBI requires clear desk and clear screen for nitrogen team security management systems |
| Phosphorus Team Security Management | RBI requires clear desk and clear screen for phosphorus team security management systems |
| Arsenic Team Security Management | RBI requires clear desk and clear screen for arsenic team security management systems |
| Antimony Team Security Management | RBI requires clear desk and clear screen for antimony team security management systems |
| Bismuth Team Security Management | RBI requires clear desk and clear screen for bismuth team security management systems |
| Moscovium Team Security Management | RBI requires clear desk and clear screen for moscovium team security management systems |
| Oxygen Team Security Management | RBI requires clear desk and clear screen for oxygen team security management systems |
| Sulfur Team Security Management | RBI requires clear desk and clear screen for sulfur team security management systems |
| Selenium Team Security Management | RBI requires clear desk and clear screen for selenium team security management systems |
| Tellurium Team Security Management | RBI requires clear desk and clear screen for tellurium team security management systems |
| Polonium Team Security Management | RBI requires clear desk and clear screen for polonium team security management systems |
| Livermorium Team Security Management | RBI requires clear desk and clear screen for livermorium team security management systems |
| Fluorine Team Security Management | RBI requires clear desk and clear screen for fluorine team security management systems |
| Chlorine Team Security Management | RBI requires clear desk and clear screen for chlorine team security management systems |
| Bromine Team Security Management | RBI requires clear desk and clear screen for bromine team security management systems |
| Iodine Team Security Management | RBI requires clear desk and clear screen for iodine team security management systems |
| Astatine Team Security Management | RBI requires clear desk and clear screen for astatine team security management systems |
| Tennessine Team Security Management | RBI requires clear desk and clear screen for tennessine team security management systems |
| Hydrogen Team Security Management | RBI requires clear desk and clear screen for hydrogen team security management systems |
| Helium Team Security Management | RBI requires clear desk and clear screen for helium team security management systems |
| Neon Team Security Management | RBI requires clear desk and clear screen for neon team security management systems |
| Argon Team Security Management | RBI requires clear desk and clear screen for argon team security management systems |
| Krypton Team Security Management | RBI requires clear desk and clear screen for krypton team security management systems |
| Xenon Team Security Management | RBI requires clear desk and clear screen for xenon team security management systems |
| Radon Team Security Management | RBI requires clear desk and clear screen for radon team security management systems |
| Oganesson Team Security Management | RBI requires clear desk and clear screen for oganesson team security management systems |
SEBI Cybersecurity Guidelines Mapping
| SEBI Requirement | Mapping to A.7.7 |
|---|---|
| Information Classification | SEBI requires clear desk and clear screen for market-sensitive data |
| Access Management | SEBI requires clear desk and clear screen for access management systems |
| Incident Management | SEBI requires clear desk and clear screen for incident management systems |
| Compliance | SEBI requires clear desk and clear screen for compliance systems |
| Third-Party Risk | SEBI requires clear desk and clear screen for third-party systems |
| Data Protection | SEBI requires clear desk and clear screen for data protection systems |
| Business Continuity | SEBI requires clear desk and clear screen for business continuity systems |
| Audit | SEBI requires clear desk and clear screen for audit systems |
| Reporting | SEBI requires clear desk and clear screen for reporting systems |
| Market Infrastructure | SEBI requires clear desk and clear screen for market infrastructure systems |
DPDP Act 2023 Mapping
| DPDP Act Provision | Mapping |
|---|---|
| Section 5, Notice | Inform data principals about processing covered by this control |
| Section 6, Consent | Obtain and manage consent for personal data processing |
| Section 8(1), Data Fiduciary responsibility | Ensure accountability for compliance with this control |
| Section 8(4), Technical and organisational measures | Implement appropriate measures to give effect to this control |
| Section 8(5), Reasonable security safeguards | Protect personal data through the safeguards in this control |
| Section 8(6), Personal data breach intimation | Detect and notify relevant breaches to the Board and affected principals |
| Section 8(7), Erasure | Erase personal data when the purpose is no longer served |
| Section 8(10), Grievance redressal mechanism | Establish an effective grievance redressal mechanism |
| Section 9, Children and persons with disability | Apply enhanced safeguards when processing children's personal data |
| Section 10, Significant Data Fiduciary | Comply with additional SDF obligations (DPO, auditor, DPIA) |
| Section 11, Right to access information | Enable data principals to obtain information about their personal data |
| Section 12, Right to correction and erasure | Enable correction, completion, updating and erasure requests |
| Section 13, Right of grievance redressal | Provide readily available grievance redressal |
| Section 14, Right to nomination | Support nomination of a representative to exercise rights |
| Section 16, Cross-border transfers | Apply safeguards when transferring personal data outside India |
| Section 27, Powers and functions of Board | Cooperate with the Data Protection Board of India |
| Section 33, Penalties | Non-compliance may attract monetary penalties under the Schedule |
Regulatory and Compliance Context
Indian Regulatory Requirements for Clear Desk and Clear Screen
Digital Personal Data Protection Act, 2023:
- The DPDP Act requires "reasonable security safeguards" for personal data, which includes physical protection measures like clear desk and clear screen policies
- Significant Data Fiduciaries must implement complete data protection measures, including physical security
- Personal data processed in offices must be protected from unauthorized physical access
- The Data Protection Board may review physical security practices during investigations
Information Technology Act, 2000:
- Section 43A (prior to DPDP Act) required protection of sensitive personal data from unauthorized access, including physical access
- Section 72 requires protection of confidentiality and privacy
- The Official Secrets Act requires protection of classified information from physical exposure
RBI Cybersecurity Framework for Banks:
- Banks must protect customer data from physical exposure in branch and back-office environments
- Branch staff must follow clear desk practices to prevent customer data from being visible to other customers or visitors
- Back-office staff must follow clear desk and clear screen policies for all customer data processing
- RBI examiners will review physical security practices, including clear desk and clear screen compliance
SEBI Cybersecurity Guidelines:
- Market infrastructure institutions must protect sensitive market data from physical exposure
- Trading floors and dealing rooms must implement clear desk and clear screen policies
- SEBI cybersecurity audits will review physical security practices
IRDAI Cybersecurity Guidelines:
- Insurance companies must protect customer and health data from physical exposure
- Claims processing and underwriting areas must implement clear desk and clear screen policies
- IRDAI cybersecurity audits will review physical security practices
NABH Accreditation Standards for Hospitals:
- Hospitals must protect patient information (PHI) from physical exposure
- Clinical workstations, nurse stations, and patient areas must implement clear screen policies
- Medical records and patient charts must be secured when not in use
- NABH assessors will review physical security practices, including clear desk and clear screen
Defense and Government (Official Secrets Act):
- Classified information must be protected from physical exposure at all times
- Desks and screens in secure areas must be cleared when unattended
- Unauthorized exposure of classified information is a criminal offense
Sector-Specific Clear Desk and Clear Screen Requirements
| Sector | Regulatory Body | Key Clear Desk/Clear Screen Requirements |
|---|---|---|
| Banking | RBI | Clear desk in branches and back offices; clear screen for all customer data workstations; secure storage for customer documents; visitor controls in back offices; audit readiness |
| Securities | SEBI | Clear desk in trading floors and dealing rooms; clear screen for all trading workstations; secure storage for market data; visitor controls; audit readiness |
| Insurance | IRDAI | Clear desk in claims and underwriting; clear screen for all customer data workstations; secure storage for health and policy data; audit readiness |
| Telecom | DoT/TRAI | Clear desk in customer service centers; clear screen for all customer data workstations; secure storage for customer records; audit readiness |
| Healthcare | CDSCO/NABH | Clear desk in clinical and administrative areas; clear screen for all PHI workstations; secure storage for medical records; HIPAA compliance for US data; audit readiness |
| Government | NCIIPC/CERT-In | Clear desk in all government offices; clear screen for all workstations; secure storage for classified and sensitive data; Official Secrets Act compliance |
| Defense | MHA/Defence | Clear desk in all defense facilities; clear screen for all workstations; secure storage for classified information; criminal penalties for exposure |
| IT/ITeS | MeitY | Clear desk in all offices; clear screen for all workstations; secure storage for customer data; export control compliance; client audit readiness |
| E-commerce | MeitY/Consumer Affairs | Clear desk in all offices; clear screen for all payment and customer data workstations; PCI DSS compliance; secure storage for customer data |
| Education | UGC/AICTE | Clear desk in administrative offices; clear screen for all student data workstations; secure storage for student records; audit readiness |
| Real Estate | RERA | Clear desk in all offices; clear screen for all customer data workstations; secure storage for customer and transaction data |
| Manufacturing | Industry Bodies | Clear desk in all offices; clear screen for all IP and design workstations; secure storage for trade secrets and design data; export control compliance |
RACI Matrix
Clear Desk and Clear Screen Activities RACI
| Activity | Board | CISO | Facilities Manager | Security Manager | IT Manager | HR Manager | All Employees | Managers | Cleaning Staff |
|---|---|---|---|---|---|---|---|---|---|
| Strategy and Policy | |||||||||
| Define clear desk/screen policy | A | R | C | C | C | C | I | I | I |
| Approve clear desk/screen policy | A | R | C | C | C | C | I | I | I |
| Design enforcement procedures | C | A | C | R | C | C | I | I | I |
| Implementation | |||||||||
| Deploy secure storage | I | C | A | C | I | I | I | I | I |
| Deploy automatic screen lock | I | A | I | C | R | I | I | I | I |
| Install signage and reminders | I | C | A | C | I | I | I | I | I |
| Deploy secure print release | I | C | C | C | R | I | I | I | I |
| Develop training | I | A | C | R | C | C | I | I | I |
| Deliver training | I | A | C | R | C | C | I | I | I |
| Operations | |||||||||
| Clear own desk and screen | I | I | I | I | I | I | R | I | I |
| Perform end-of-day procedure | I | I | I | I | I | I | R | I | I |
| Conduct spot checks | I | C | A | R | I | I | I | R | I |
| Conduct formal audits | I | A | C | R | I | I | I | I | I |
| Monitor compliance | I | A | C | R | I | I | I | I | I |
| Address violations | I | A | C | R | I | R | I | R | I |
| Manage cleaning staff | I | I | A | C | I | I | I | I | R |
| Audit and Compliance | |||||||||
| Prepare audit evidence | I | A | C | R | C | I | I | I | I |
| Respond to findings | A | R | C | C | C | I | I | I | I |
| Report to management | A | R | C | C | I | I | I | I | I |
R = Responsible, A = Accountable, C = Consulted, I = Informed
Documentation and Record Keeping
Required Documentation
| Document | Purpose | Retention Period | Owner |
|---|---|---|---|
| Clear Desk and Clear Screen Policy | Defines the policy and requirements | 7 years | CISO |
| End-of-Day Procedure | Step-by-step procedure for employees | 3 years | Security Manager |
| Training Materials | Training content for employees | 3 years | Security Manager |
| Training Completion Records | Records of who completed training | 3 years | HR |
| Spot Check Records | Records of informal spot checks | 1 year | Security Manager |
| Formal Audit Records | Records of formal compliance audits | 3 years | Security Manager |
| Compliance Metrics Reports | Monthly/quarterly compliance reports | 3 years | Security Manager |
| Violation Records | Records of policy violations and remediation | 7 years | Security Manager |
| Disciplinary Action Records | Records of disciplinary actions for violations | 7 years | HR |
| Exception Records | Approved exceptions to the policy | 3 years | CISO |
| Signage and Reminder Inventory | Inventory of signage and reminders deployed | 1 year | Facilities Manager |
| Secure Storage Inventory | Inventory of lockable storage (drawers, cabinets, lockers) | 1 year | Facilities Manager |
| Screen Lock Configuration | Technical configuration for screen lock enforcement | 3 years | IT Manager |
| Secure Print Release Configuration | Technical configuration for secure print | 3 years | IT Manager |
| Visitor and Contractor Agreements | Agreements acknowledging the policy | Duration + 3 years | Security Manager |
| Cleaning Staff Training Records | Training records for cleaning staff | 3 years | Facilities Manager |
| Policy Review Records | Records of annual policy reviews | 3 years | CISO |
| Incident Correlation Records | Records of incidents related to clear desk/screen violations | 7 years | Security Manager |
| Audit Reports | Internal and external audit reports | 7 years | Compliance |
Record Keeping Best Practices
- Centralized Repository: Maintain clear desk/screen records in a centralized system (shared drive, document management system, or security management system)
- Access Control: Restrict access to compliance records based on role and need-to-know
- Version Control: Track version history for the policy, procedures, and training materials
- Audit Trail: Maintain complete audit trails for compliance monitoring, violations, and remediation
- Backup: Clear desk/screen records are important for compliance and must be backed up
- Privacy Compliance: Handle personal data in compliance records per DPDP Act
- Legal Privilege: Protect compliance records related to litigation or investigation
- Cross-Reference: Link compliance records to incident records, training records, and audit reports
- Retention Compliance: Align retention with legal and regulatory requirements
- Secure Destruction: Securely destroy records when retention periods expire
- Real-Time Access: Enable real-time access to compliance metrics for management reporting
- Reporting: Enable automated reporting on compliance rates and trends
- Integration: Integrate compliance records with security awareness, incident management, and HR systems
- Searchability: Ensure compliance records are searchable by employee, department, date, and violation type
- Dashboards: Provide real-time dashboards for compliance status and trends
Continuous Improvement
Figure · Tiers
Maturity levels for clear desk and clear screen
- OptimizingNear-perfect compliance (≥99%)
- ManagedHigh compliance rates (≥95%)
- DefinedComplete policy with clear requirements
- DevelopingBasic policy exists but is not enforced
- InitialNo clear desk/screen policy
Maturity Model for A.7.7
| Level | Name | Characteristics | Evidence |
|---|---|---|---|
| 1 | Initial | No clear desk/screen policy; no enforcement; no training; desks and screens routinely left unsecured; high visual hacking risk | No documentation, no controls, no enforcement, frequent violations |
| 2 | Developing | Basic policy exists but is not enforced; some training provided; some employees comply; spot checks are occasional; compliance is inconsistent | Basic policy, some training, some compliance, some checks |
| 3 | Defined | Complete policy with clear requirements; automatic screen lock deployed; secure storage available; training for all employees; regular spot checks and formal audits; violation handling; quarterly review | Complete policy, automation, storage, training, monitoring, enforcement, review |
| 4 | Managed | High compliance rates (≥95%); automated monitoring of screen lock compliance; secure print release deployed; visitor management integrated; cleaning staff trained; metrics-driven; positive reinforcement culture; integration with security awareness program | High compliance, automation, integration, metrics, culture, positive reinforcement |
| 5 | Optimizing | Near-perfect compliance (≥99%); self-policing culture where employees correct each other; visitors and contractors automatically comply; remote work fully covered; policy is a competitive advantage; industry-leading practices; continuous optimization | Self-policing, near-perfect compliance, competitive advantage, industry-leading |
Improvement Cycle
Plan:
- Annual policy and procedure review
- Benchmarking against industry standards and peer organizations
- Regulatory change assessment and alignment (DPDP Act, RBI, SEBI, NABH)
- Technology evaluation for automation and enhancement (IoT, smart storage, biometric locks)
- Maturity assessment and target setting
- Incident analysis for lessons learned
- Workspace risk assessment updates (new layouts, new areas, remote work changes)
Do:
- Implement new automation tools (screen lock enforcement, secure print, smart storage)
- Expand training to new employees and refresher for existing employees
- Enhance signage and reminders with new designs and placements
- Deploy new secure storage solutions (personal lockers, smart cabinets)
- Extend policy to new areas (remote work, co-working spaces, new offices)
- Enhance visitor and contractor controls
- Improve cleaning staff training and supervision
- Conduct security awareness campaigns focused on clear desk/screen
- Implement positive reinforcement programs (recognition, rewards, contests)
Check:
- Monthly compliance metrics review (clear desk rate, clear screen rate, violation trends)
- Quarterly formal audit results review
- Annual complete policy and procedure review
- Compliance audit preparation and results
- Employee feedback and comprehension assessment
- overhead optimization and ROI measurement
- Incident correlation analysis (violations vs. incidents)
- Remote work compliance assessment
- Visitor and contractor compliance assessment
- Culture assessment (self-policing, peer awareness, positive reinforcement)
Act:
- Update policy based on findings, incidents, and emerging risks
- Refine procedures based on employee feedback and incident lessons
- Invest in tools that improve automation, accuracy, and monitoring
- Expand training for high-risk roles, new hires, and remote workers
- Report improvements to leadership and board
- Share best practices and lessons learned
- Benchmark against industry standards and peer organizations
- Engage with regulatory bodies on compliance
- Participate in industry forums on physical security best practices
- Publish illustrative scenarios and research on clear desk/screen effectiveness
Toolkit Download
The following toolkit assets are available for this control:
| Asset | Description | Format |
|---|---|---|
| 01-clear-desk-clear-screen-policy-template.md | Complete policy template with enforcement procedures | Markdown |
| 02-end-of-day-checklist-template.docx | End-of-day security checklist for employees | Word |
| 03-spot-check-checklist-template.docx | Spot check and audit checklist for security/facilities | Word |
| 04-training-presentation-clear-desk-screen.pptx | Training deck with scenarios and knowledge test | PowerPoint |
| 05-screen-lock-configuration-guide.md | GPO/MDM screen lock configuration guide | Markdown |
| 06-signage-and-reminder-templates.zip | Desk plates, posters, stickers, and keyboard sticker designs | ZIP (PNG/PDF) |
| 07-secure-print-release-guide.md | Secure print release deployment guide | Markdown |
| 08-visitor-contractor-agreement-template.docx | Visitor and contractor acknowledgment template | Word |
| 09-meeting-room-security-guide.md | Meeting room and whiteboard security guide | Markdown |
| 10-remote-work-clear-desk-guide.md | Remote work and home office adaptation guide | Markdown |
| 11-compliance-metrics-dashboard.xlsx | Dashboard for tracking clear desk/screen KPIs | Excel |
| 12-violation-handling-flowchart.docx | Violation handling flowchart and disciplinary matrix | Word |
| 13-cleaning-staff-training-guide.md | Cleaning staff training and supervision guide | Markdown |
| 14-audit-evidence-checklist.md | Evidence checklist for A.7.7 audit preparation | Markdown |
| 15-exception-request-form.docx | Exception request and approval form | Word |
| 16-incident-response-template.docx | Visual hacking/physical exposure incident response template | Word |
| 17-maturity-assessment-questionnaire.md | Self-assessment for clear desk/screen program maturity | Markdown |
| README.md | Index and usage guide for all toolkit assets | Markdown |
Frequently Asked Questions
Q1: Is clear desk and clear screen mandatory for ISO 27001 certification?
A: Yes. A.7.7 explicitly requires "a clear desk policy for papers and removable storage media and a clear screen policy for information processing facilities" to be "adopted and appropriately enforced." This is a core control that auditors will always review during physical security assessments. A single unattended desk with a sensitive document or an unlocked screen can be a finding.
Q2: How short should the automatic screen lock timeout be?
A: The timeout depends on the risk level of the environment:
- High-risk environments (BPO, trading floors, healthcare, areas with high visitor traffic): 2–3 minutes
- Standard office environments: 5 minutes
- Low-risk environments (private offices with no visitor access): 10 minutes
- Public/shared terminals: 1 minute The timeout should be short enough to prevent unauthorized access during brief absences (bathroom breaks, coffee runs) but not so short that it frustrates users and causes them to find workarounds. For most organizations, 5 minutes is the standard recommendation. For high-risk environments, 2–3 minutes is appropriate. Test the timeout with a pilot group before full deployment.
Q3: Do we need to provide lockable storage for every employee?
A: Yes, every employee who handles sensitive information must have access to lockable storage. At minimum, every desk should have at least one lockable drawer. In open-plan or hot-desking environments, personal lockers should be provided. The storage does not need to be premium-tier, a simple lockable desk drawer or a small filing cabinet is sufficient. The key is that employees have somewhere to put sensitive documents and media when they leave their desk. Without lockable storage, the policy is unenforceable.
Q4: How do we handle employees who say the policy is too inconvenient?
A: Inconvenience is a common complaint, but it can be addressed by: (1) making secure storage easily accessible (lockable drawer at the desk, not a cabinet across the room), (2) making screen lock automatic (not manual), (3) explaining the "why", real-world examples of breaches caused by visual hacking and document theft, (4) sharing compliance metrics that show the policy works, (5) making the end-of-day procedure a quick 2-minute routine, not a 30-minute chore, (6) providing positive reinforcement for compliance, not just punishment for violations. The key is to make compliance easier than non-compliance. If locking a drawer takes 5 seconds and the alternative is a disciplinary warning, employees will lock the drawer.
Q5: Should we enforce clear desk at the end of the day, or also during the day when employees leave for lunch or breaks?
A: Both. The policy should require clearing the desk whenever the employee is not present, even for short periods. This includes lunch breaks, coffee breaks, bathroom breaks, meetings, and any other absence from the desk. The rationale is that an attacker or visitor only needs a few seconds to photograph a document or copy a USB drive. However, the policy should be practical: documents actively being worked on can remain on the desk while the employee is present, but must be secured when the employee leaves. The end-of-day clearance is the most critical (all items secured overnight), but daytime clearance is also important.
Q6: How do we handle open-plan offices where desks are visible to everyone?
A: Open-plan offices are the highest-risk environment for clear desk violations because every desk is visible to everyone. In open-plan offices: (1) enforce the strictest clear desk policy (no sensitive documents visible when unattended), (2) provide personal lockers or lockable drawers for every employee, (3) use desk dividers or privacy screens to reduce visual exposure, (4) position screens to face away from main walkways (not toward reception or visitor areas), (5) use privacy filters on screens to reduce angle visibility, (6) conduct frequent spot checks, (7) train employees on the risks of open-plan layouts. Open-plan offices are popular for overhead and collaboration, but they require the most rigorous clear desk enforcement.
Q7: What about hot-desking and shared workstations?
A: Hot-desking and shared workstations require adapted controls: (1) employees must clear the desk completely before leaving (no personal or sensitive items left behind), (2) screens must log out after each session (not just lock), (3) personal lockers must be provided for storing items between shifts, (4) shared workstations should have "session end" buttons that log out and clear temporary files, (5) USB ports may be disabled on shared workstations to prevent media storage, (6) each user should use their own credentials and not share accounts. Hot-desking environments are actually easier for clear desk enforcement because employees are already in the habit of taking their belongings with them when they leave.
Q8: How do we handle remote workers and home offices?
A: Remote workers must follow an adapted clear desk/clear screen policy: (1) lock screens when leaving the workstation, even at home, (2) secure sensitive documents in a locked drawer or cabinet when not in use, (3) ensure screens and documents are not visible to family members, visitors, or delivery personnel, (4) collect and secure all materials when working in shared spaces (co-working, coffee shops), (5) use privacy filters on screens in shared spaces, (6) do not leave work devices unattended in public spaces. Provide remote workers with guidance on home office setup, including secure storage recommendations. Include remote workers in training and compliance monitoring (via self-assessment or periodic check-ins).
Q9: How do we handle meeting rooms with whiteboards and flip charts?
A: Meeting rooms are a common source of data exposure. Controls: (1) all whiteboards must be erased after meetings; provide erasers and signs, (2) flip chart pages with sensitive content must be removed and stored securely or shredded, (3) digital whiteboards must be configured to clear content after meetings, (4) meeting rooms must be checked after each meeting for left-behind documents, laptops, or devices, (5) meeting rooms should have "erase after use" signs, (6) for highly sensitive meetings, consider non-permanent markers or digital whiteboards that don't retain physical traces. Assign a "meeting owner" responsibility to ensure the room is cleared.
Q10: How do we measure the effectiveness of clear desk and clear screen?
A: Key effectiveness indicators: (1) Clear desk compliance rate, percentage of desks compliant during spot checks (target: ≥95%), (2) Clear screen compliance rate, percentage of screens locked during spot checks (target: ≥99%), (3) End-of-day compliance rate, percentage of employees performing end-of-day procedure (target: ≥95%), (4) Violation rate, number of violations per month (target: decreasing trend), (5) Repeat violation rate, percentage of violations that are repeat offenses (target: ≤10%), (6) Training completion rate, percentage of employees completing training (target: ≥95%), (7) Training test score, average score on knowledge test (target: ≥90%), (8) Visual hacking incidents, number of visual hacking incidents detected (target: 0), (9) Document theft incidents, number of document theft incidents (target: 0), (10) Audit findings, number of clear desk/screen-related audit findings (target: 0). Measure baseline before implementation and track trends over time. Report improvements to leadership quarterly.
Q11: What should we do when visitors or auditors request to see documents or screens?
A: Visitors and auditors should never be allowed to view sensitive documents or screens without authorization. If an auditor needs to review documents, they must be provided in a controlled manner (e.g., in a meeting room, with an authorized employee present, with only the specific documents needed). If an auditor needs to see a system, they must be shown a demo or test environment, not the production system with live data. Visitors should be restricted to designated visitor areas. If a visitor needs to see a work area, they must be escorted, and the area should be prepared in advance (desks cleared, screens locked, sensitive documents removed). Never allow an unescorted visitor to walk through a work area.
Q12: How do we handle clear desk during emergencies (fire alarm, evacuation)?
A: During emergencies, personal safety takes priority over clear desk compliance. Employees should not delay evacuation to secure documents. However, the organization should consider: (1) the fire alarm or evacuation drill may be used as a social engineering tactic to clear the office for theft, so security personnel should monitor the area during evacuations, (2) after the emergency, employees should check their desks and report any missing items, (3) for planned drills, employees can practice "quick clear" procedures (taking critical items with them), (4) emergency procedures should be documented and communicated. The key is to balance safety with security, never require employees to risk safety for document security, but have post-incident procedures to address any exposure during the emergency.
Q13: Should we use screen privacy filters?
A: Screen privacy filters are recommended for high-risk environments (open-plan offices, customer-facing desks, areas with high visitor traffic). Privacy filters limit the viewing angle of the screen, so only the person directly in front of the screen can see the content. They are particularly useful for: (1) open-plan offices where screens are visible to neighbors, (2) reception and customer service desks where screens may be visible to customers, (3) areas where shoulder surfing is a risk, (4) employees who work with highly sensitive data (finance, HR, legal). Privacy filters are not a substitute for screen locks, they should be used in combination with screen locks. They are relatively inexpensive (–per screen) and can be installed by the user.
Q14: How do we handle cleaning staff who need to clean desks?
A: Cleaning staff are a common challenge for clear desk policies because they need to access desks to clean them. Solutions: (1) cleaning staff should be screened and trained on the clear desk policy, (2) cleaning staff should be supervised or work in teams, (3) cleaning should be scheduled during work hours when employees are present (if feasible), or after hours with security supervision, (4) cleaning staff should not access locked drawers or cabinets, (5) cleaning staff should report any sensitive documents found on desks to security or facilities, (6) cleaning staff should be required to sign confidentiality agreements. In high-security environments, cleaning staff may be escorted or limited to specific areas. The key is to balance the need for cleaning with the need for security.
Q15: How do we maintain compliance over the long term?
A: Long-term compliance requires: (1) Automation, automatic screen lock removes the human factor for screens, (2) Integration, make clear desk/screen part of the organizational culture, not a separate security initiative, (3) Reinforcement, periodic reminders, training, and awareness campaigns keep the topic fresh, (4) Metrics, track and publish compliance rates to maintain accountability, (5) Leadership modeling, executives and managers must visibly comply with the policy to set the tone, (6) Positive culture, create a culture where employees remind each other and take pride in security, rather than viewing it as a burden, (7) New hire training, every new employee learns the policy from day one, (8) Continuous improvement, review and refine the policy based on incidents, feedback, and changes in the work environment. Compliance is not a one-time project, it is a continuous practice that requires ongoing attention.
The following toolkit assets are available for this control:
| # | Toolkit File | Description |
|---|---|---|
| 1 | 01-clear-desk-and-clear-screen-policy-template.md | Policy Template |
| 2 | 02-clear-desk-and-clear-screen-procedure.md | Procedure |
| 3 | 03-clear-desk-and-clear-screen-checklist.md | Checklist |
| 4 | 04-audit-evidence-checklist.md | Audit Evidence Checklist |
| 5 | 05-implementation-roadmap.md | Implementation Roadmap |
| 6 | 06-quick-reference-card.md | Quick Reference Card |
| 7 | 07-training-materials.md | Training Materials |
| 8 | 08-incident-response-playbook.md | Incident Response Playbook |
| 9 | 09-risk-assessment-template.md | Risk Assessment Template |
| 10 | 10-vendor-security-template.md | Vendor Security Template |
| 11 | 11-metrics-and-kpi-dashboard.md | Metrics and KPI Dashboard |
| 12 | 12-gap-analysis-template.md | Gap Analysis Template |
| 13 | 13-raci-matrix.md | RACI Matrix |
| 14 | 14-tool-comparison-matrix.md | Tool Comparison Matrix |
| 15 | 15-communication-plan.md | Communication Plan |
| 16 | 16-roles-and-responsibilities.md | Roles and Responsibilities |
| 17 | 17-regulatory-mapping.md | Regulatory Mapping |
References and Further Reading
Standards and Frameworks
- ISO/IEC 27001:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements
- ISO/IEC 27002:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Controls
- NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations
- COBIT 2019, IT Governance and Management Framework
- CIS Controls v8, Controls 1 (Inventory and Control of Enterprise Assets) and 4 (Secure Configuration)
- PCI DSS v4.0, Physical Security Requirements for Cardholder Data Environment
- HIPAA Security Rule, Physical Safeguards (Workstation Security, Device and Media Controls)
- GDPR, Article 32 (Security of Processing, including physical security)
Indian Legal and Regulatory References
- Digital Personal Data Protection Act, 2023
- Information Technology Act, 2000 (as amended through 2008)
- Official Secrets Act, 1923 (for government and defense classified information)
- RBI Cybersecurity Framework for Banks (2016, updated)
- SEBI Cybersecurity Guidelines for Market Infrastructure Institutions (2019)
- IRDAI Cybersecurity Guidelines for Insurance Companies (2017)
- NABH Accreditation Standards for Hospitals (relevant to patient information protection)
- Indian Penal Code, 1860 (relevant sections on theft and breach of trust)
- Companies Act, 2013 (relevant to data protection and board responsibility)
Industry and Research Sources
- Ponemon Institute, Visual Hacking Study (2019, 2023)
- SANS Institute, Physical Security and Visual Hacking Resources
- ISACA, Physical Security Governance and Risk Management Guidance
- Gartner Research, Physical Security and Workplace Security
- Forrester Research, Security Awareness and Behavioral Change
- IBM Research, Security Culture and Employee Behavior
- Verizon Data Breach Investigations Report (physical security and insider threat statistics)
- "Visual Hacking: The Simplest Form of Data Breach", Security Magazine
- "The Psychology of Clear Desk Policies", Journal of Information Security and Privacy
- "Physical Security in the Modern Workplace", ASIS International
Tool Documentation
- Microsoft Group Policy Documentation, Screen Saver and Screen Lock Configuration
- Microsoft Intune Documentation, Device Compliance and Screen Lock Policies
- VMware Workspace ONE Documentation, Device Management and Security Policies
- Jamf Pro Documentation, macOS Security and Screen Lock Configuration
- MobileIron Documentation, Mobile Device Security and Screen Lock
- Various printer manufacturer documentation for Secure Print Release (HP, Canon, Ricoh, Xerox)
- Various CCTV and visitor management system documentation
Open Source Resources
- Custom PowerShell scripts for Windows screen lock enforcement and monitoring
- Custom Bash scripts for Linux screen lock configuration
- Custom scripts for screen lock compliance auditing and reporting
- Custom scripts for printer secure print release configuration
- Open-source visitor management systems (e.g., SimpleVisitor, VisitorLog)
- Open-source security awareness training platforms (e.g., SecurityEducation, PhishTank)
- Custom scripts for compliance metric tracking and dashboard generation
Document Control
- Version: 1.0
- Author: Singahi, ISO 27001 Implementation Experts
- Review Cycle: Quarterly + Annual
- Next Review: September 2026 (quarterly) / June 2027 (annual)
- Classification: TLP:CLEAR, Public Information