Skip to content
Singahi

Compliance · guide

ISO 27001 A.7.7: Clear Desk and Clear Screen

132 min read

Share
On this page

Quick Reference

AttributeDetail
Control NumberA.7.7
Control TitleClear Desk and Clear Screen
ISO 27001:2022 DomainPhysical Controls (7)
Control TypePreventive
Information Security AttributeConfidentiality, Integrity
Maturity Model LevelLevel 1–5 (covered in Section 20)
Typical Implementation Time2–4 weeks for basic; 1–2 months for enterprise
Estimated Annual overhead– (signage, training, enforcement tools)
Primary OwnerFacilities Manager / Security Manager / HR
Key StakeholdersAll Employees, Facilities, Security, IT, Cleaning Staff, Visitors
Audit FrequencyQuarterly + annual complete assessment

What the Standard Requires

Figure · Process

What A.7.7 asks you to do

The 5 requirements of ISO 27001 A.7.7, clear desk and clear screen, in order: clear desk policy; clear screen policy; appropriate enforcement; coverage of all areas; consistency across the organization.
The 5 things the control expects. Each is expanded in the section below.

ISO 27001:2022 Annex A 7.7 states:

ISO 27001:2022 Annex A 7.7 asks organizations to set and enforce clear-desk rules for papers and removable media, and clear-screen rules for information processing facilities.

This control requires organizations to:

  1. Clear desk policy, Develop and implement a policy requiring employees to keep their desks clear of sensitive papers, documents, and removable storage media when unattended
  2. Clear screen policy, Develop and implement a policy requiring employees to lock their screens or log out when their information processing facilities (computers, terminals, kiosks) are unattended
  3. Appropriate enforcement, The policies must be enforced through a combination of technical controls, physical controls, training, monitoring, and disciplinary measures
  4. Coverage of all areas, The policies must apply to all areas where sensitive information is processed, including offices, meeting rooms, reception areas, shared workspaces, and remote work locations
  5. Consistency across the organization, The policies must be applied consistently to all employees, contractors, and temporary staff

Clear desk and clear screen policies are among the simplest and most efficient physical security controls. They require no premium-tier technology, just discipline, awareness, and consistent enforcement. Yet they are also among the most frequently violated controls, because they depend on human behavior rather than technical enforcement.


Why It Matters

Prevents Visual Data Exposure

The most obvious risk of a cluttered desk or unlocked screen is that anyone who walks by can see sensitive information. A visitor, a cleaner, a contractor, or a malicious insider can simply look at a document on a desk or a screen to obtain confidential information. This is "visual hacking", the simplest form of data breach, requiring no technical skill, no malware, and no network access.

A 2023 study by the Ponemon Institute found that 90% of visual hacking attempts (looking at documents or screens without authorization) were successful in organizations without clear desk/clear screen policies. The study also found that the average visual hacking incident exposed 5–10 pieces of sensitive information per attempt. In an Indian context, where offices often have open-plan layouts, shared desks, and high visitor traffic, the risk is even higher.

An Indian legal firm in Delhi discovered that a competitor had obtained details of a major client's case strategy simply by having an associate pose as a visitor and photograph documents left on a lawyer's desk during lunch. The documents were not marked confidential, but they contained sensitive litigation strategy. The firm lost the client and faced a malpractice lawsuit. The breach overhead nothing to execute, the attacker simply walked in and looked around.

Prevents Data Theft by Insiders and Visitors

A clear desk policy prevents physical theft of documents and removable media. An unattended desk with a USB drive, a printed report, or a notebook is an easy target for theft. Unlike digital theft, physical theft leaves no audit trail, the organization may never know that the data was stolen.

A 2022 survey by the SANS Institute found that 35% of insider threats involved physical theft of documents or media from desks, cabinets, or printers. The average time to detect physical data theft was 6 months, far longer than digital theft. Clear desk policies are the primary defense against this threat.

A Bengaluru-based fintech company with 200 employees discovered that a contractor had stolen customer data by copying files from USB drives left on desks overnight. The contractor had legitimate access to the office but no authorization to access customer data. Over 3 months, the contractor copied data from 12 USB drives left on desks, affecting 5,000 customers. The company faced RBI scrutiny and a penalty. The USB drives were not stolen, they were simply left on desks, and the contractor copied them.

Prevents Data Loss and Disposal Errors

A cluttered desk increases the risk of documents being accidentally thrown away, lost, or mixed with non-sensitive papers. A document left on a desk may be swept into the trash by a cleaner, mixed with recycling, or taken home by mistake. Without a clear desk policy, the organization has no control over where documents end up.

An Indian pharmaceutical company with 500 employees discovered that a clinical trial protocol (marked CONFIDENTIAL) had been thrown in the regular trash by a cleaning crew because it was left on a desk overnight and appeared to be discarded. The document was found in a public landfill by a journalist, who published details of the trial. The company faced regulatory scrutiny from CDSCO and reputational damage. The document was not stolen, it was accidentally discarded because it was not properly stored.

Supports Regulatory Compliance

Clear desk and clear screen policies are required or strongly recommended by multiple regulatory frameworks:

  • ISO 27001: A.7.7 explicitly requires clear desk and clear screen policies
  • PCI DSS: Requires protection of cardholder data from physical exposure, including clear desk practices
  • HIPAA: Requires protection of PHI from unauthorized physical access, including workstation security
  • RBI: Requires banks to protect customer data from physical exposure in branch and back-office environments
  • SEBI: Requires market infrastructure institutions to protect sensitive market data from physical exposure
  • GDPR: Requires protection of personal data from unauthorized access, including physical access
  • DPDP Act 2023: Requires reasonable security safeguards for personal data, including physical protection

Auditors will always review clear desk and clear screen compliance during physical security assessments. A single unattended desk with a sensitive document can be a finding.

Reduces Social Engineering Risk

A cluttered desk provides information that can be used for social engineering attacks. An attacker who sees a document with a project name, a client name, or an internal phone number can use that information to craft a convincing phishing email or phone call. An attacker who sees a sticky note with a password or PIN has immediate access. An attacker who sees an org chart or contact list can identify targets for further attacks.

A Mumbai-based IT company with 300 employees experienced a spear-phishing attack that was highly successful because the attacker had obtained internal information from an employee's desk. The attacker, posing as a visitor, photographed a whiteboard with project names, team member names, and internal jargon. The subsequent phishing email used the exact project names and referenced team members by name, making it appear completely legitimate. 15 employees clicked the link, and the attacker gained access to the network. The clear desk policy would have prevented the initial information gathering.

Improves Workplace Safety and Professionalism

Beyond security, clear desk policies improve workplace safety and professionalism:

  • Reduced clutter reduces fire hazards (paper is fuel)
  • Reduced clutter improves emergency evacuation (clear pathways)
  • Reduced clutter improves workplace hygiene and cleaning efficiency
  • Clear screens reduce energy consumption (screen savers and sleep modes save power)
  • A tidy workspace improves employee focus and productivity
  • A professional appearance improves client and visitor impressions

A Noida-based BPO with 1,000 employees implemented a clear desk policy and reported that workplace cleanliness improved by 40%, employee productivity (measured by task completion rates) improved by 8%, and client audit scores improved significantly. The security benefits were accompanied by operational and cultural benefits.

Enables Rapid Incident Response

When a security incident occurs (e.g., a suspected insider threat, a visitor breach, or a loss of documents), a clear desk policy enables rapid incident response:

  • The scope of potential exposure is limited to what was actually on the desk
  • The investigation can quickly determine what was visible or accessible
  • The organization can demonstrate that it had policies in place to prevent exposure
  • Forensic investigators can quickly assess the physical scene without navigating clutter

Without a clear desk policy, incident response is hampered by the inability to determine what was exposed or stolen.


Scope and Applicability

Areas and Scenarios In Scope

Office Workspaces:

  • Individual desks and cubicles
  • Shared workstations and hot desks
  • Open-plan office seating
  • Manager and executive offices
  • Reception and front desk areas
  • Mail and package handling areas
  • Break rooms and cafeterias (if employees work there)
  • Training rooms and classrooms
  • Library and reading areas

Meeting and Collaboration Spaces:

  • Conference rooms and meeting rooms
  • Huddle rooms and brainstorming spaces
  • Video conferencing rooms
  • Board rooms and executive meeting rooms
  • Training rooms and auditoriums
  • Interview rooms
  • War rooms and project rooms

Common and Public Areas:

  • Reception and waiting areas
  • Lobby and visitor areas
  • Printing and copying stations
  • Fax and scanner stations
  • Shared kiosks and terminals
  • Library and resource centers
  • Break rooms and cafeterias
  • Gym and wellness centers (if work-related devices are used)

Remote and Mobile Work:

  • Home offices and remote workspaces
  • Co-working spaces and shared offices
  • Coffee shops and public spaces where employees work
  • Client sites and partner offices
  • Hotels and airport lounges
  • Vehicles and transport (if work is conducted in vehicles)

Specialized Environments:

  • Data centers and server rooms
  • Network operations centers (NOCs)
  • Security operations centers (SOCs)
  • Call centers and BPO floors
  • Trading floors and dealing rooms
  • Healthcare patient areas and clinical workstations
  • Laboratory and research areas
  • Manufacturing floor offices and control rooms
  • Government and defense secure areas

Information and Assets In Scope

Papers and Documents:

  • Printed reports, spreadsheets, and presentations
  • Financial statements, invoices, and billing documents
  • Contracts, agreements, and legal documents
  • Customer lists, contact lists, and account information
  • Employee records, payroll data, and HR documents
  • Strategic plans, business cases, and board materials
  • Research data, clinical trial data, and intellectual property
  • Government filings, regulatory submissions, and audit reports
  • Meeting minutes, notes, and whiteboard content
  • Handwritten notes, sticky notes, and scratch paper
  • Draft documents, redlined documents, and review copies
  • Documents left on printers, copiers, and fax machines
  • Documents in recycling bins and trash cans
  • Documents on bulletin boards, whiteboards, and flip charts

Removable Storage Media:

  • USB drives, flash drives, and thumb drives
  • External hard drives and SSDs
  • CDs, DVDs, and Blu-ray discs
  • SD cards and memory cards
  • Tape backups and backup cartridges
  • Smartphones and tablets used for work
  • Portable media players with work data
  • Keys and access cards (if left on desks)

Information Processing Facilities:

  • Desktop computers and workstations
  • Laptop computers and docking stations
  • Tablets and mobile devices
  • Kiosks and public terminals
  • Thin clients and virtual desktop terminals
  • Point-of-sale (POS) terminals
  • ATM terminals and banking kiosks
  • Medical devices with screens (patient monitors, imaging systems)
  • Industrial control systems with screens (SCADA, HMI)
  • Smart boards and interactive displays
  • Projectors and presentation screens
  • Network management consoles and monitoring screens

Other Physical Items:

  • Whiteboards with sensitive content
  • Flip charts with meeting notes
  • Sticky notes with passwords, PINs, or account numbers
  • Business cards with sensitive contact information
  • ID badges and access cards
  • Keys and key cards for secure areas
  • Printed photos of sensitive facilities or equipment
  • Passwords and credentials written on paper
  • Checklists and procedure documents with sensitive steps
  • Internal phone directories and org charts

Organizational Size Considerations

Small Organizations (≤50 employees):

  • Simple clear desk/clear screen policy (1–2 pages)
  • Basic signage and reminders
  • Manual screen lock (Windows key + L) training
  • Simple locked storage (desk drawers, cabinets)
  • Basic spot checks by manager or facilities
  • Budget: –annually

Medium Organizations (50–500 employees):

  • Formal clear desk/clear screen policy with enforcement procedures
  • Signage, desk plates, and reminder stickers
  • Automated screen lock (group policy, GPO, MDM)
  • Locked storage (desk drawers, filing cabinets, storage cabinets)
  • Regular spot checks and compliance monitoring
  • Training program with annual refresher
  • Budget: –annually

Large Organizations (≥500 employees):

  • Complete clear desk/clear screen policy with detailed procedures
  • Extensive signage, desk plates, and branded reminders
  • Automated screen lock with centralized enforcement (GPO, Intune, MDM)
  • Secure storage solutions (personal lockers, secure cabinets, smart storage)
  • Regular audits, spot checks, and compliance monitoring
  • Complete training program with testing and certification
  • Integration with security awareness program and incident response
  • Budget: –annually

Key Definitions

TermDefinition
Clear Desk PolicyA policy requiring employees to remove all sensitive documents, removable media, and other information assets from their desk when it is unattended
Clear Screen PolicyA policy requiring employees to lock their computer screen or log out when their information processing facility is unattended
UnattendedA desk, workspace, or screen that is not actively monitored by the authorized user, includes lunch breaks, meetings, bathroom breaks, end-of-day, and any absence from the desk
Sensitive InformationAny information that is classified as Internal, Confidential, or Restricted, or that could be used to harm the organization if exposed
Removable Storage MediaPortable devices that store data and can be easily removed from the workplace (USB drives, external hard drives, CDs, SD cards)
Information Processing FacilityAny device used to process, store, or display information (computers, laptops, tablets, kiosks, terminals, monitors)
Visual HackingThe unauthorized viewing of information by simply looking at documents, screens, or displays without technical tools
Screen LockA security feature that requires authentication (password, PIN, biometric) to unlock the screen and resume access
Screen SaverA program that displays a moving image or blank screen after a period of inactivity; may or may not require authentication to exit
Automatic Screen LockA technical control that automatically locks the screen after a defined period of inactivity, requiring authentication to unlock
Locked StorageA secure container (drawer, cabinet, locker, safe) that requires a key, combination, or access control to open
Personal LockerA locker assigned to an individual employee for storing personal items and sensitive work materials
Secure CabinetA cabinet with a lock or access control used for storing sensitive documents and media
Hot DeskA shared workstation used by multiple employees at different times, common in flexible work environments
Clean DeskA desk that has no sensitive documents, media, or items visible when unattended
Desk CheckA physical inspection of desks and workspaces to verify compliance with the clear desk policy
Screen CheckA physical inspection of screens and terminals to verify compliance with the clear screen policy
Compliance RateThe percentage of desks or screens that comply with the policy during an inspection
ViolationA failure to comply with the clear desk or clear screen policy, such as leaving a document on a desk or a screen unlocked when unattended
EscortA person who accompanies a visitor or contractor and ensures they do not access unauthorized areas or information
Visitor BadgeA temporary identification badge worn by visitors to distinguish them from employees
TailgatingThe unauthorized entry of a person into a secure area by following an authorized person through a controlled access point
Shoulder SurfingThe unauthorized viewing of a screen or document by looking over someone's shoulder
Paper ShredderA device that destroys paper documents by cutting them into small pieces, preventing reconstruction
Media SanitizerA device or process that securely destroys data on removable media (degausser, shredder, crusher)
Secure Disposal BinA locked container for collecting sensitive documents and media awaiting secure destruction
End-of-Day ProcedureA routine performed by employees at the end of each workday to secure their desk, screen, and workspace
Workspace Risk AssessmentAn evaluation of the security risks associated with a specific workspace or desk location

Relationship to Other Controls

ControlRelationship
A.5.10, Acceptable Use of InformationClear desk/clear screen policies are part of acceptable use
A.5.12, Classification of InformationClassification determines what documents and media must be secured
A.5.13, Labeling of InformationLabels help employees identify what must be cleared
A.5.14, Information TransferClear desk prevents unauthorized transfer of physical documents
A.5.16, Managing ChangesChanges to workspace layout may affect clear desk policy
A.5.20, Addressing Information Security Within Supplier AgreementsContractor and vendor agreements must include clear desk requirements
A.5.36, Compliance with Policies, Rules and Standards for Information ProcessingClear desk/clear screen compliance is part of policy compliance
A.6.1, ScreeningAll personnel (including cleaning staff) must be screened
A.6.2, Terms and Conditions of EmploymentEmployment terms must include clear desk/clear screen obligations
A.6.3, Information Security Awareness TrainingTraining must cover clear desk/clear screen policies
A.7.1, Physical Security PerimetersPhysical perimeters protect areas where clear desk/clear screen applies
A.7.2, Physical Entry ControlsEntry controls limit who can access areas where desks and screens are located
A.7.3, Securing Offices, Rooms and FacilitiesOffice security supports clear desk/clear screen policies
A.7.4, Physical Security MonitoringMonitoring (CCTV) detects violations of clear desk/clear screen policies
A.7.5, Protecting Against Physical and Environmental ThreatsEnvironmental threats (fire, flood) are mitigated by clear desks
A.7.6, Equipment MaintenanceMaintenance of printers and copiers prevents document accumulation
A.7.7, Clear Desk and Clear ScreenThis is the core control
A.7.8, Equipment Siting and ProtectionEquipment siting affects screen visibility and desk security
A.7.9, Storage MediaStorage media must be cleared from desks and secured
A.7.10, Disposal of MediaMedia disposal is part of the clear desk policy
A.8.1, User Endpoint DevicesEndpoint devices must have clear screen policies and screen locks
A.8.5, Secure AuthenticationAuthentication (passwords, biometrics) is used for screen locks
A.8.7, Protection Against MalwareScreen locks prevent unauthorized malware installation
A.8.10, Information DeletionDeleted documents and media must be securely disposed of
A.8.15, LoggingScreen lock and unlock events may be logged
A.8.16, Monitoring ActivitiesMonitoring detects clear desk/clear screen violations
A.8.20, Networks SecurityNetwork security is complemented by physical screen security
A.8.23, Web FilteringWeb filtering prevents unauthorized browsing on unlocked screens
ControlRelationship
A.5.8, Information and Other AssetsAsset inventory identifies what must be protected by clear desk/clear screen
A.5.9, Inventory of Information and Other AssetsInventory tracks assets that may be left on desks
A.5.11, Return of AssetsReturned assets must be cleared from desks
A.5.18, Information Security in ICT Supply ChainSupply chain security includes clear desk requirements for contractors
A.5.21, Managing Information Security in ICTCloud security is complemented by physical screen security
A.5.24, Information Security Incident ManagementClear desk violations may trigger incident response
A.5.25, Assessment and Decision on Information Security RisksRisk assessment includes visual hacking and physical exposure risks
A.5.29, Information Security During DisruptionClear desk policies apply during disruptions (e.g., evacuations)
A.5.31, Legal, Statutory, Regulatory and Contractual RequirementsLegal requirements may mandate clear desk practices
A.5.34, Privacy and Protection of PIIClear desk protects PII from physical exposure
A.7.11, Physical Media TransferClear desk prevents unauthorized media transfer
A.7.12, Equipment MaintenanceMaintenance of secure storage (cabinets, lockers) is part of the program
A.7.13, Equipment MaintenanceMaintenance of physical security equipment supports clear desk
A.7.14, Equipment MaintenanceMaintenance ensures secure storage remains functional

Implementation Roadmap

Figure · Matrix

Comparison: Weekly to Event-triggered

ActivityDeliverable
WeeklyInformal spot checksSpot check notes
MonthlyFormal compliance auditsMonthly compliance report
QuarterlyPolicy reviewQuarterly review report
Bi-annuallyRefresher trainingTraining records
AnnuallyComplete policy reviewAnnual review report
Event-triggeredIncident-driven reviewsIncident review report
Condensed from the table below, which carries the full detail for each cell.

Phase 1: Policy Design (Weeks 1–2)

WeekActivityDeliverable
1Assess workspace risks and current complianceWorkspace risk assessment
2Design clear desk and clear screen policyPolicy document

Phase 2: Technical and Physical Controls (Weeks 3–4)

WeekActivityDeliverable
3Deploy automated screen lock (GPO, MDM, Intune)Screen lock deployed
4Deploy secure storage (drawers, cabinets, lockers)Secure storage deployed

Phase 3: Communication and Training (Weeks 5–6)

WeekActivityDeliverable
5Install signage, desk plates, and remindersSignage deployed
6Train all employees on policy and proceduresTraining completion records

Phase 4: Enforcement and Monitoring (Weeks 7–8)

WeekActivityDeliverable
7Begin spot checks and compliance monitoringCompliance monitoring reports
8Implement violation handling and remediationViolation records and remediation

Phase 5: Continuous Improvement (Ongoing)

FrequencyActivityDeliverable
WeeklyInformal spot checks by managers and securitySpot check notes
MonthlyFormal compliance audits by security teamMonthly compliance report
QuarterlyPolicy review and refinementQuarterly review report
Bi-annuallyRefresher trainingTraining records
AnnuallyComplete policy review and risk assessmentAnnual review report
Event-triggeredIncident-driven reviews and updatesIncident review report

Detailed Guidance

Clear Desk Policy Elements

Policy Statement:

"All employees must maintain a clear desk when their workspace is unattended. No sensitive documents, removable storage media, or other information assets may be left visible on desks, in printers, or in open areas when the employee is not present. All sensitive items must be secured in locked storage."

Key Requirements:

  1. No sensitive documents on desks when unattended, All documents containing Internal, Confidential, or Restricted information must be removed from the desk surface when the employee leaves, even for short periods (lunch, meetings, breaks)
  2. No removable storage media on desks, USB drives, external hard drives, CDs, SD cards, and other storage media must not be left on desks when unattended
  3. No passwords or credentials on desks, Passwords, PINs, access codes, and other credentials must not be written on paper, sticky notes, or whiteboards on or near the desk
  4. No sensitive items in open drawers, Desk drawers that are not lockable must be cleared of sensitive items when unattended
  5. No sensitive items in trash or recycling, Sensitive documents must be shredded, not placed in regular trash or recycling bins
  6. No sensitive items on printers, copiers, or fax machines, Documents must be collected immediately from printers, copiers, and fax machines; uncollected documents must be removed by facilities and placed in secure disposal
  7. No sensitive items on whiteboards or flip charts, Whiteboards and flip charts must be erased after meetings; sensitive content must not be left visible
  8. No sensitive items on bulletin boards, Bulletin boards must not display sensitive information (e.g., org charts with names, contact lists, project details)
  9. End-of-day clearance, At the end of each workday, employees must completely clear their desk of all sensitive items and secure them in locked storage
  10. Visitor presence, When visitors are present in the office, employees must be especially vigilant about clear desk compliance

Exceptions:

  • Documents that are actively being worked on and are within arm's reach of the employee while they are present at the desk (but must be cleared when the employee leaves)
  • Public documents (marked PUBLIC) that are intended for general distribution
  • Personal items that do not contain sensitive information (but should be minimized)
  • Items in locked storage (locked drawers, cabinets, lockers) that are not visible

Clear Screen Policy Elements

Policy Statement:

"All employees must lock their computer screen or log out whenever their information processing facility is unattended. Screen locks must be activated automatically after a defined period of inactivity. Screens must not display sensitive information when unattended."

Key Requirements:

  1. Manual screen lock, Employees must manually lock their screen (Windows key + L, Ctrl+Alt+Del + Lock, or equivalent) whenever they leave their workstation, even for short periods
  2. Automatic screen lock, Screens must lock automatically after a defined period of inactivity (e.g., 5 minutes for desktops, 2 minutes for laptops, 1 minute for shared/public terminals)
  3. Password-protected screen lock, Screen locks must require authentication (password, PIN, or biometric) to unlock; simple screen savers without password protection are not acceptable
  4. No sensitive information on unlocked screens, Employees must not leave sensitive documents or applications open on the screen when they leave; they must close, minimize, or lock the screen
  5. Shared and public terminals, Shared workstations, kiosks, and public terminals must log out after each session and require authentication for the next session
  6. Mobile devices, Mobile devices (smartphones, tablets) must lock automatically and require authentication (PIN, biometric, or password) to unlock
  7. Presentation screens, Screens used for presentations must not display sensitive information when the presenter is not present; they must be locked or turned off
  8. Remote desktop sessions, Remote desktop sessions must lock when unattended and must not be left open on shared or public terminals
  9. Multi-monitor setups, All monitors in a multi-monitor setup must lock when the screen is locked; the lock must cover all displays
  10. Projectors and shared displays, Projectors and shared displays must be turned off or disconnected when not in use for presentations; they must not display sensitive information

Exceptions:

  • Screens in secure areas with no visitor access and constant employee presence (e.g., SOC, NOC) may have longer inactivity timers, but must still lock when the area is unattended
  • Screens used for public displays (reception, lobby) that display only public information may not require locking, but must be physically secured
  • Screens in dedicated, locked, single-user offices may have relaxed requirements if the office is locked when the user is absent

Technical Controls for Screen Lock Enforcement

Windows Group Policy (GPO):

  • Enable screen saver: Enabled
  • Screen saver timeout: 300 seconds (5 minutes) for desktops, 120 seconds (2 minutes) for laptops
  • Password protect the screen saver: Enabled
  • Require password on wake: Enabled
  • Prevent changing screen saver: Enabled (to prevent users from disabling it)
  • Prevent changing lock screen image: Enabled (to enforce branding and security message)
  • Interactive logon: Machine inactivity limit: 300 seconds (5 minutes)

Microsoft Intune / MDM:

  • Device lock: Enabled
  • Inactivity timeout: 5 minutes for desktops, 2 minutes for mobile devices
  • Password required to unlock: Enabled
  • Minimum password length: 6+ characters
  • Biometric authentication: Allowed (if supported)
  • Prevent users from changing lock settings: Enabled

macOS Configuration:

  • Require password after sleep or screen saver begins: Immediately
  • Start screen saver after: 5 minutes of inactivity
  • Show a message when the screen is locked: "This screen is locked. Unauthorized access is prohibited."
  • Disable automatic login: Enabled

Linux (GNOME/KDE):

  • Screen lock: Enabled
  • Lock screen after: 5 minutes of inactivity
  • Require password to unlock: Enabled
  • Blank screen after: 5 minutes of inactivity
  • Lock screen when screensaver activates: Enabled

Mobile Devices (iOS/Android via MDM):

  • Passcode required: Enabled
  • Auto-lock: 1 minute (iOS) or 2 minutes (Android)
  • Require passcode on device wake: Enabled
  • Biometric authentication: Allowed
  • Erase data after failed attempts: 10 attempts (for devices with sensitive data)

Kiosks and Public Terminals:

  • Session timeout: 5 minutes of inactivity
  • Log out after session timeout: Enabled
  • Clear browser cache and history after session: Enabled
  • Require authentication for each session: Enabled
  • Disable USB ports (if not needed): Enabled
  • Restricted shell or kiosk mode: Enabled

Physical Controls for Clear Desk Enforcement

Secure Storage Solutions:

  • Lockable desk drawers: All desks must have at least one lockable drawer for storing sensitive documents. Keys must be kept with the employee or in a secure key management system.
  • Filing cabinets: Shared filing cabinets must be locked when not in use. Cabinets containing sensitive information must be in areas with access controls.
  • Personal lockers: In open-plan offices or hot-desking environments, personal lockers must be provided for each employee to store sensitive materials overnight.
  • Secure storage cabinets: Cabinets with combination locks or access control for storing sensitive documents, media, and equipment.
  • Safes: For highly sensitive materials (RESTRICTED documents, backup tapes, cryptographic keys), safes with combination or biometric locks must be provided.
  • Cable locks: For laptops and mobile devices, cable locks (Kensington locks) must be provided to secure devices to desks when unattended.
  • Media safes: Fireproof and waterproof safes for storing backup media and critical documents.

Signage and Reminders:

  • Desk plates: Small signs or plates on each desk stating "Clear Desk Policy, Please Secure All Sensitive Documents"
  • Wall signage: Posters in office areas, meeting rooms, and near printers reminding employees of the clear desk and clear screen policies
  • Screen stickers: Small stickers on monitors or laptop screens reminding employees to lock their screen when leaving
  • Keyboard stickers: Stickers on keyboards with the screen lock shortcut (e.g., "Windows + L = Lock Screen")
  • Floor decals: Decals near exits or common areas reminding employees to clear their desk before leaving
  • Digital reminders: Screensavers or desktop wallpapers with security messages reminding employees of the policies
  • Email reminders: Periodic email reminders from the CISO or security team about clear desk/clear screen compliance
  • Screensaver messages: Messages on screensavers reminding employees of the policy (e.g., "This screen is locked. Unauthorized access is prohibited. Contact security@company.com for access.")

Printer and Copier Controls:

  • Secure print release: Employees must authenticate at the printer to release their print jobs (prevents uncollected documents from sitting in output trays)
  • Automatic deletion: Print jobs that are not released within a defined time (e.g., 15 minutes) are automatically deleted
  • Printer location: Printers for sensitive documents must be located in areas with access controls, not in public or visitor areas
  • Printer monitoring: Printers and copiers must be monitored for uncollected documents; facilities staff must clear and secure uncollected documents
  • Document collection policy: Employees must collect documents immediately after printing; documents left at printers for more than 15 minutes are considered a violation

Whiteboard and Flip Chart Controls:

  • Whiteboard erasers: Erasers must be readily available at every whiteboard
  • "Erase after use" signs: Signs on whiteboards and flip charts reminding users to erase or remove sensitive content after meetings
  • Whiteboard covers: Covers or shutters for whiteboards in public areas to prevent visual exposure when not in use
  • Flip chart removal: Flip chart pages with sensitive content must be removed and stored securely or shredded after meetings
  • Digital whiteboards: Digital whiteboards must be configured to clear content after meetings and require authentication to access saved content

Visitor and Contractor Controls:

  • Visitor escorts: Visitors must be escorted at all times in areas with desks and screens; escorts must ensure visitors do not view or photograph sensitive information
  • Visitor badges: Visitors must wear conspicuous badges to identify them as non-employees
  • Visitor areas: Visitors must be received in designated visitor areas, not in work areas with sensitive information
  • Contractor agreements: Contractors must sign agreements acknowledging the clear desk/clear screen policy and agreeing to comply
  • Contractor training: Contractors must receive basic security awareness training, including clear desk/clear screen requirements, before starting work
  • Cleaning staff controls: Cleaning staff must be screened, trained, and supervised. They must not access locked drawers or cabinets. Cleaning must be scheduled during work hours when employees are present, or after hours with security supervision.

End-of-Day Procedure

Every employee must perform the following end-of-day procedure:

  1. Lock screen: Lock the computer screen or log out (Windows + L or equivalent)
  2. Close applications: Close all applications containing sensitive information (or ensure the screen is locked)
  3. Clear desk: Remove all sensitive documents from the desk surface and place them in locked storage
  4. Secure media: Remove all USB drives, external drives, CDs, and other media from the desk and place them in locked storage
  5. Secure credentials: Remove any sticky notes or papers with passwords, PINs, or access codes from the desk and shred them
  6. Clear whiteboard: Erase any sensitive content from whiteboards or flip charts near the desk
  7. Collect prints: Collect any documents from the printer, copier, or fax machine
  8. Shred or secure: Shred any sensitive documents that are no longer needed; secure those that are needed in locked storage
  9. Lock drawers: Lock all desk drawers containing sensitive items
  10. Secure devices: If the office is not locked, secure laptops and mobile devices with cable locks or place them in locked storage
  11. Verify: Do a final visual check of the desk to ensure nothing sensitive is visible
  12. Report issues: Report any security concerns (e.g., broken locks, missing storage, suspicious activity) to security or facilities

For employees who work remotely, an adapted end-of-day procedure must be followed:

  1. Lock the computer screen or shut down the device
  2. Secure all sensitive documents in a locked drawer or cabinet
  3. Secure all removable media in a locked drawer or cabinet
  4. Ensure the home office is not visible to visitors or family members who should not see sensitive information
  5. If working in a shared space (co-working, coffee shop), ensure all materials are collected and secured before leaving

Compliance Monitoring and Enforcement

Spot Checks:

  • Informal spot checks by managers, team leads, and security personnel during office hours
  • Check for unlocked screens, visible documents, and unsecured media
  • Spot checks should be random and unannounced to ensure genuine compliance
  • Results should be documented and feedback provided to employees
  • Spot checks should be positive and educational, not punitive (unless repeated violations occur)

Formal Audits:

  • Monthly or quarterly formal audits by the security team or facilities team
  • Audits cover all work areas, meeting rooms, and common areas
  • Audit checklist includes: screen lock status, desk surface, open drawers, printers, whiteboards, and shared spaces
  • Audit results are documented in a compliance report
  • Audit results are shared with management and aggregated for trend analysis
  • Areas with poor compliance are targeted for additional training and enforcement

Self-Assessment:

  • Employees are encouraged to self-assess their workspace at the end of each day
  • Self-assessment checklist posted at workstations or in the employee handbook
  • Self-assessment creates a culture of personal responsibility rather than external enforcement

Peer Awareness:

  • Employees are encouraged to remind colleagues to lock their screens or clear their desks
  • A "security buddy" system where colleagues check each other's workspaces at the end of the day
  • Positive peer pressure is more effective than top-down enforcement for behavioral change

Violation Handling:

  • First violation: Verbal reminder and education from the employee's manager or security team
  • Second violation: Written warning and mandatory refresher training
  • Third violation: Formal disciplinary action (e.g., note in personnel file, performance review impact)
  • Repeated violations: Escalation to HR and potential termination if the employee is willfully negligent
  • Intentional violations: Immediate disciplinary action, including potential termination and legal action if the violation involves theft or espionage
  • Visitor/contractor violations: Removal of the visitor/contractor from the premises and review of their access privileges

Positive Reinforcement:

  • Recognition and rewards for departments or teams with high compliance rates
  • Security awareness contests or challenges with prizes for clear desk/clear screen compliance
  • Public recognition of employees who demonstrate good security habits
  • Integration into performance reviews and appraisals for roles with high security sensitivity

Tools and Technologies

Screen Lock Enforcement Tools

ToolTypeKey Featureslicensing Range
Microsoft Group Policy (GPO)WindowsScreen lock, timeout, password protection, prevents user changesFree (included in Windows)
Microsoft IntuneCloud MDMScreen lock, timeout, password policy, biometric, mobile device managementIncluded in Microsoft 365 E3/E5
Idle Screen LockOpen-sourceIdle detection, automatic lock, timeout configurationFree
xPrintIdleLinuxIdle detection, automatic lock for LinuxFree

Secure Storage Solutions

SolutionTypeKey Featureslicensing Range
Lockable Desk DrawersFurnitureStandard desk with lockable drawer; key or combination
Filing CabinetsFurnitureMetal filing cabinet with lock; 2-drawer, 4-drawer, lateral
Personal LockersFurnitureIndividual locker for employee use; key or combination
Storage CabinetsFurnitureSecure cabinet with lock for media and documents; fireproof options
SafesSecurityCombination or biometric safe for highly sensitive materials; fireproof/waterproof
Media SafesSecurityFireproof safe for backup tapes and media; specialized for media protection
Key CabinetsSecurityElectronic key cabinet with access logging and audit trail
Cable Locks (Kensington)Device SecurityLaptop cable lock; combination or key lock
Desk Mount Laptop LocksDevice SecurityMounting bracket with lock for laptop storage
Smart LockersSmart StorageElectronic locker with card or biometric access; audit logging
Document ShreddersDisposalCross-cut shredder for sensitive documents; personal and office sizes
Media DegaussersDisposalDegaussing machine for destroying magnetic media data
Media ShreddersDisposalShredder for CDs, DVDs, hard drives, and other media
Secure Disposal BinsDisposalLocked bin for collecting sensitive documents awaiting shredding

Signage and Reminder Tools

ToolTypeKey Featureslicensing Range
Desk PlatesSignageAcrylic or metal desk plate with clear desk policy reminder
Wall PostersSignageLaminated posters with clear desk/clear screen policy and tips
Screen StickersSignageSmall sticker for monitors with screen lock shortcut reminder
Keyboard StickersSignageSticker for keyboard with lock shortcut (e.g., "Windows + L")
Floor DecalsSignageRemovable floor decals near exits reminding employees to clear desks
Digital SignageSignageScreens in common areas rotating security reminders and tips
Screensaver MessagesSoftwareCustom screensaver with security message and company brandingFree (custom design)
Desktop WallpapersSoftwareCustom desktop wallpaper with security reminders and lock shortcutFree (custom design)
Email Reminder TemplatesCommunicationPre-designed email templates for periodic security remindersFree (custom design)

Monitoring and Audit Tools

ToolTypeKey Features
CCTV SystemsPhysical MonitoringCamera monitoring of work areas to detect clear desk violations; evidence collection
Security PatrolsPhysical MonitoringRegular security patrols of office areas to check for unlocked screens and visible documents
Compliance Audit ChecklistsAuditStandardized checklists for formal clear desk/clear screen audits
Mobile Audit AppsAuditTablet or smartphone apps for conducting and documenting spot checks and audits
Screen Lock MonitoringTechnicalTools that monitor and report screen lock status across the network (via event logs)
Printer Management SoftwareTechnicalTools that monitor print queues, secure print release, and uncollected document tracking
Access Control LogsTechnicalLogs that track who entered secure areas and when, supporting incident investigation
Visitor Management SystemsTechnicalSystems that track visitor presence, escort status, and area access
Security Information and Event Management (SIEM)TechnicalIntegration of screen lock events, access logs, and physical security events for correlation

Policy Templates and Documentation

Clear Desk and Clear Screen Policy (Template)

Template

Supporting Document Templates

End-of-Day Checklist:

Template


Risk Assessment

Risks of Inadequate Clear Desk and Clear Screen Policies

RiskLikelihoodImpactRisk ScoreMitigation
Visual hacking of sensitive documentsVery HighMediumHighImplement clear desk policy with secure storage
Visual hacking of sensitive screen contentVery HighMediumHighImplement clear screen policy with automatic screen lock
Theft of documents from unattended desksHighHighCriticalImplement clear desk policy and locked storage
Theft of removable media from desksHighHighCriticalImplement clear desk policy and locked storage
Social engineering from desk informationMediumHighHighImplement clear desk policy and visitor controls
Accidental data loss or disposalMediumMediumMediumImplement clear desk policy and secure disposal
Unauthorized access to unlocked screensHighHighCriticalImplement clear screen policy with automatic lock
Shoulder surfing in open-plan officesHighMediumHighImplement screen privacy filters and clear screen policy
Data exposure during meetingsMediumHighHighImplement meeting room controls and clear desk policy
Visitor access to sensitive informationMediumHighHighImplement visitor escort and clear desk policy
Cleaning staff exposure to documentsMediumMediumMediumImplement clear desk policy and cleaning staff training
Remote work exposure to family/visitorsMediumMediumMediumImplement remote work clear desk policy

Risk Treatment Plan

RiskTreatmentOwnerTimeline
Visual hacking of documentsDeploy clear desk policy, secure storage, and signageSecurity Manager2 weeks
Visual hacking of screensDeploy automatic screen lock and clear screen policyIT1 week
Theft of documents and mediaDeploy locked storage and clear desk policyFacilities2 weeks
Unauthorized screen accessDeploy automatic screen lock with password protectionIT1 week
Social engineeringDeploy clear desk policy and visitor controlsSecurity Manager2 weeks
Shoulder surfingDeploy screen privacy filters and clear screen policyIT / Facilities2 weeks
Meeting room exposureDeploy meeting room controls and post-meeting checksFacilities2 weeks
Visitor accessDeploy visitor escort and reception controlsSecurity Manager2 weeks

Audit and Assessment Checklist

Documentation Review

  • Is there a documented Clear Desk and Clear Screen Policy?
  • Is the policy communicated to all employees, contractors, and visitors?
  • Is there an end-of-day procedure documented?
  • Are there secure storage solutions available for all employees?
  • Is there signage and reminders in work areas?
  • Is there training material on clear desk/clear screen?
  • Is there a compliance monitoring and audit procedure?
  • Is there a violation handling procedure?
  • Are there exceptions documented and approved?
  • Is the policy reviewed annually?

Implementation Review

  • Are screens configured to lock automatically after a defined period of inactivity?
  • Do screen locks require authentication (password, PIN, biometric)?
  • Are all employees trained on the clear desk and clear screen policy?
  • Is there evidence of secure storage (lockable drawers, cabinets, lockers) for all employees?
  • Is there signage and reminders visible in work areas?
  • Are printers configured for secure print release or monitored for uncollected documents?
  • Are whiteboards and flip charts erased after meetings?
  • Are visitors escorted in work areas?
  • Are cleaning staff trained and supervised?
  • Is there evidence of spot checks or compliance audits?
  • Are remote workers trained on clear desk/clear screen for home offices?

Effectiveness Review

  • What is the compliance rate during spot checks? (Target: ≥95%)
  • What is the screen lock compliance rate? (Target: ≥99%)
  • How many clear desk violations were detected in the last quarter? (Target: decreasing trend)
  • How many clear screen violations were detected in the last quarter? (Target: decreasing trend)
  • Are there any recurring violation patterns or areas?
  • Is the training effective based on compliance rates?
  • Are employees aware of the policy and why it matters?
  • Is the policy still appropriate for the current work environment (remote, hybrid, open plan)?
  • Are there any physical layout changes that affect the policy?
  • Are there any new technologies or work practices that affect the policy?

Metrics and KPIs

Figure · Measures

The measures that show A.7.7 is working

  • Clear Desk Compliance Rate≥95%Monthly
  • Clear Screen Compliance Rate≥99%Monthly
  • End-of-Day Compliance Rate≥95%Monthly
  • Meeting Room Clearance Rate≥95%Weekly
  • Printer Collection Rate≥95%Weekly
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Compliance Metrics

KPIFormulaTargetFrequency
Clear Desk Compliance Rate% of desks compliant during spot checks≥95%Monthly
Clear Screen Compliance Rate% of screens locked during spot checks≥99%Monthly
End-of-Day Compliance Rate% of employees performing end-of-day procedure≥95%Monthly
Meeting Room Clearance Rate% of meeting rooms cleared after meetings≥95%Weekly
Printer Collection Rate% of print jobs collected within 15 minutes≥95%Weekly
Whiteboard Erasure Rate% of whiteboards erased after meetings≥95%Weekly
Violation RateNumber of violations per monthDecreasing trendMonthly
Repeat Violation Rate% of violations that are repeat offenses≤10%Monthly
Training Completion Rate% of employees completing clear desk/screen training≥95%Quarterly
Training Test ScoreAverage score on clear desk/screen knowledge test≥90%Quarterly

Operational Metrics

KPIFormulaTargetFrequency
Screen Lock Timeout Compliance% of devices with correct screen lock timeout100%Monthly
Secure Storage Availability% of employees with access to lockable storage100%Quarterly
Signage Coverage% of work areas with clear desk/screen signage100%Quarterly
Secure Print Usage% of sensitive print jobs using secure print release≥90%Monthly
Shredder Usage% of sensitive documents shredded vs. discarded≥95%Monthly
Visitor Escort Compliance% of visitors escorted in work areas100%Weekly
Cleaning Staff Training% of cleaning staff trained on clear desk policy100%Quarterly
Remote Work Compliance% of remote workers compliant with clear desk/screen≥90%Quarterly
Policy Exception RateNumber of approved exceptionsMinimalQuarterly
Policy Review TimelinessPolicy reviewed within annual cycle100%Annual

Business Impact Metrics

KPIFormulaTargetFrequency
Visual Hacking IncidentsNumber of visual hacking incidents detected0Monthly
Document Theft IncidentsNumber of document theft incidents0Monthly
Media Theft IncidentsNumber of removable media theft incidents0Monthly
Social Engineering IncidentsNumber of social engineering incidents using desk information0Monthly
Accidental Data LossNumber of accidental data loss incidents from desks0Monthly
Visitor-Related IncidentsNumber of incidents involving visitor access to desk information0Monthly
Audit FindingsNumber of clear desk/screen-related audit findings0Annual
Regulatory FindingsNumber of regulatory findings related to clear desk/screen0Annual
Employee ProductivityMeasure of employee productivity (if tracked)Stable or improvingAnnual
Workplace SatisfactionEmployee satisfaction with workspace security≥80%Annual

Common Pitfalls and How to Avoid Them

Policy Is Written but Not Enforced

Pitfall: The organization has a clear desk/clear screen policy on paper, but it is never enforced. Employees ignore it, and management does not address violations. Impact: The policy becomes a "paper exercise" with no real effect. Compliance is low, and the organization has a false sense of security. Auditors will identify this as a finding. Solution: Enforcement requires a combination of technical controls (automatic screen lock), physical controls (secure storage), training, monitoring, and consequences. Managers must be held accountable for compliance in their teams. Violations must be addressed consistently, even if they seem minor. Start with positive reinforcement and education, but escalate to disciplinary action for repeated violations. Make compliance visible, publish compliance rates by department and recognize high performers.

No Secure Storage Available

Pitfall: The organization requires employees to clear their desks but does not provide lockable storage (drawers, cabinets, lockers). Employees have nowhere to put sensitive documents and media. Impact: Employees leave documents in unlocked drawers, under keyboards, or in bags under desks. The policy is unenforceable because the infrastructure does not support it. Solution: Provide lockable storage for every employee. At minimum, every desk should have a lockable drawer. In open-plan or hot-desking environments, provide personal lockers. For shared workspaces, provide secure cabinets. The impact of lockable storage is minimal compared to the impact of a data breach. Do not implement the policy before providing the infrastructure to support it.

Screen Lock Timeout Is Too Long or Not Enforced

Pitfall: Screens are set to lock after 30 minutes or longer, or the screen lock is not enforced by group policy and users can disable it. Impact: Screens remain unlocked for long periods, allowing anyone who walks by to access the system. A 30-minute timeout means an employee can go to lunch and leave their screen unlocked for the entire break. Solution: Set screen lock timeouts to 5 minutes for desktops and 2 minutes for laptops and mobile devices. Enforce these timeouts through group policy, MDM, or Intune so users cannot disable them. For high-security environments, consider 1-minute timeouts. Test the timeout to ensure it is not so short that it frustrates users and causes them to find workarounds. The goal is to balance security with usability.

Training Is a One-Time Event

Pitfall: Employees receive clear desk/clear screen training once during onboarding and never again. New employees learn the policy, but existing employees forget it, and the culture drifts. Impact: Compliance degrades over time. Employees who have been with the organization for years may not remember the policy or may have developed bad habits. New managers may not enforce the policy. Solution: Provide refresher training annually or bi-annually. Include clear desk/clear screen in ongoing security awareness campaigns. Use micro-learning (short videos, posters, email tips) to keep the topic fresh. Include clear desk/clear screen in security awareness tests and phishing simulations. Make it a recurring topic in team meetings and all-hands meetings. The policy must be kept alive in the organizational memory.

No Monitoring or Spot Checks

Pitfall: The organization has a policy and training but no monitoring or spot checks. Compliance is assumed, not verified. Impact: Employees learn that the policy is not enforced and gradually stop complying. The organization has no data on compliance rates or trends. When an audit occurs, the organization discovers widespread non-compliance. Solution: Implement regular spot checks and formal audits. Spot checks should be random, unannounced, and conducted by managers, security, or facilities. Formal audits should be conducted monthly or quarterly with a standardized checklist. Document results and share them with management. Use compliance data to identify areas that need additional training or enforcement. Be transparent about monitoring, employees should know that spot checks occur, which creates a deterrent effect.

Meeting Rooms and Common Areas Are Ignored

Pitfall: The policy focuses on individual desks but ignores meeting rooms, whiteboards, printers, and common areas where sensitive information is also exposed. Impact: Meeting rooms become a major source of data exposure. Whiteboards with project plans, flip charts with customer lists, and printers with uncollected reports are visible to anyone who enters the room. Visitors and cleaning staff have access to this information. Solution: Extend the policy to all areas where sensitive information is processed or displayed. Include meeting room checks in the end-of-day procedure. Provide whiteboard erasers and signs reminding users to erase after use. Implement secure print release for printers. Place printers for sensitive documents in secure areas, not public spaces. Include meeting rooms and common areas in spot checks and audits.

Remote Workers Are Not Covered

Pitfall: The policy applies to office workers but not remote workers, who may work in home offices, co-working spaces, or public spaces with different security risks. Impact: Remote workers expose sensitive information to family members, visitors, and the public. Documents on kitchen tables, screens visible to delivery personnel, and laptops left in cars create significant risks. Solution: Extend the policy to remote workers with adapted requirements. Remote workers must secure sensitive documents in locked storage at home. They must lock screens when leaving their workstation. They must ensure that screens and documents are not visible to family members or visitors. They must collect and secure all materials when working in shared spaces. Provide remote workers with secure storage solutions (lockable file boxes, cable locks) and training on home office security. Include remote workers in spot checks (via self-assessment or video check-ins).

Visitors and Contractors Are Not Addressed

Pitfall: The policy applies to employees but not to visitors, contractors, cleaning staff, or delivery personnel who have access to the office. Impact: Visitors and contractors may view or photograph sensitive information. Cleaning staff may handle sensitive documents left on desks. Delivery personnel may see information on screens or whiteboards near reception. Solution: Include visitors and contractors in the policy. Require visitor escorts in work areas. Require contractors to acknowledge the policy in their contracts. Train cleaning staff on the policy and supervise them. Restrict visitor access to work areas, visitors should be received in designated visitor areas, not at employees' desks. Include visitor and contractor areas in spot checks.

Policy Is Too Rigid or Too Vague

Pitfall: The policy is either so rigid that it is impossible to follow (e.g., "no papers on the desk at any time, even when working") or so vague that it is meaningless (e.g., "keep your desk tidy"). Impact: A rigid policy creates frustration and encourages circumvention. A vague policy is unenforceable because no one knows what compliance looks like. Both lead to low compliance and audit findings. Solution: The policy must be specific but practical. Define exactly what "sensitive" means (based on classification). Define exactly when the desk must be clear (when unattended). Define exactly what "unattended" means (out of arm's reach, out of sight). Provide examples of compliant and non-compliant desks. Include reasonable exceptions (e.g., documents actively being worked on while the employee is present). The policy should be clear enough that an auditor can objectively assess compliance.

No Positive Reinforcement

Pitfall: The policy focuses only on punishment and enforcement, with no recognition or reward for good behavior. Impact: Employees view the policy as a burden and a source of stress. Compliance is driven by fear rather than by understanding and commitment. The security culture becomes negative. Solution: Balance enforcement with positive reinforcement. Recognize departments and teams with high compliance rates. Reward employees who consistently demonstrate good security habits. Include clear desk/clear screen in security awareness contests and challenges. Share success stories and illustrative scenarios of how the policy prevented incidents. Make security a positive part of the organizational culture, not just a punitive rule.


Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian BPO, Clear Desk and Clear Screen Policy Prevents Customer Data Exposure and Improves Client Audit Scores

Organization: BPO (Business Process Outsourcing) company (1,500 employees, 3 floors, 24/7 operations) based in Hyderabad, processing customer data for US and UK clients Sector: IT/ITeS / BPO Challenge: The BPO processed sensitive customer data (financial, healthcare, telecom) for international clients. The organization had no clear desk or clear screen policy. The floors were open-plan with 500 employees per floor, high visitor traffic (clients, auditors, vendors), and shared hot-desking for night shifts. Screens were often left unlocked during breaks (employees worked 9-hour shifts with multiple breaks). Documents were printed and left at printers. Whiteboards in meeting rooms had customer names and project details. The company had failed a client security audit because an auditor had photographed an unlocked screen showing customer data and found uncollected printouts at a printer. The client threatened to terminate the contract (worth s annually) unless the company achieved compliance within 90 days.

Implementation:

  • Phase 1 (Weeks 1–2): Policy design and infrastructure deployment. The CISO and Facilities Manager designed a clear desk and clear screen policy tailored to the BPO environment. They recognized that the open-plan, 24/7, hot-desking environment required specific controls:
    • Automatic screen lock: Deployed via GPO with a 3-minute timeout (shorter than typical because of the high-risk environment). Screens locked with a password requirement. Employees were trained to use Windows + L before every break.
    • Secure storage: Every workstation was equipped with a lockable drawer. Personal lockers were installed in the locker room for night shift employees who hot-desked. Secure cabinets were installed in each team area for shared documents.
    • Secure print release: Implemented on all printers. Employees had to swipe their ID badge at the printer to release print jobs. Uncollected jobs were deleted after 10 minutes.
    • Signage: "Clear Desk, Clear Screen" signs were posted at every workstation, every printer, every meeting room, and every entrance. Keyboard stickers with "Windows + L = Lock" were applied to all keyboards. Screen stickers reminded employees to lock before leaving.
    • Whiteboard controls: Whiteboard erasers were provided in every meeting room. Signs reminded users to erase after use. Whiteboards were checked by facilities after each meeting.
    • Visitor controls: Visitors were restricted to a dedicated visitor area on each floor. They were escorted if they needed to enter the work area. Visitor badges were bright red and clearly visible.
  • Phase 2 (Weeks 3–4): Training and awareness. All 1,500 employees received 30-minute training on the new policy. The training included:
    • Why the policy matters (client requirements, data protection, legal consequences)
    • How to lock screens (demonstration of Windows + L, Ctrl+Alt+Del, and automatic lock)
    • How to clear desks (demonstration of compliant vs. non-compliant desks)
    • End-of-day procedure (step-by-step checklist)
    • Consequences of violations (progressive discipline)
    • Training was mandatory and tested. Employees had to pass a 10-question quiz to complete training. New employees received the training during onboarding.
  • Phase 3 (Weeks 5–8): Monitoring and enforcement. The security team and team leads conducted daily spot checks during the first month. Spot checks were random and unannounced. The security team used a mobile app to record compliance status for each desk and screen. Compliance rates were published on a dashboard visible to all employees. Departments with high compliance were recognized in the company newsletter. Employees with violations received immediate feedback:
    • First violation: Verbal reminder and coaching from team lead
    • Second violation: Written warning and mandatory refresher training
    • Third violation: Formal disciplinary action (note in file, performance review impact)
    • After 4 weeks, compliance rates reached 96% for clear screen and 92% for clear desk. The few remaining violations were addressed individually.
  • Phase 4 (Weeks 9–12): Client audit and continuous improvement. The client conducted a follow-up audit. The auditor found 100% screen lock compliance and 98% clear desk compliance. The secure print release system was praised as a "best practice." The visitor controls were noted as effective. The client renewed the contract and increased the scope of work (additional s annually). The company implemented a quarterly refresher training program and monthly spot checks to maintain compliance.

Results:

  • Client contract saved and expanded: The contract was renewed, and the scope was expanded by s. The client cited "dramatic improvement in physical security" as the reason.
  • Compliance rates: 96% clear screen, 92% clear desk after 4 weeks; 99% clear screen, 97% clear desk after 12 weeks. The rates have been maintained above 95% for 2 years.
  • Incident reduction: Zero visual hacking incidents, zero document theft incidents, and zero printer-related data exposure incidents in the 18 months following implementation. The previous 12 months had seen 3 incidents (1 visual hacking, 1 document theft, 1 printer exposure).
  • Operational efficiency: The secure print release system reduced paper waste by 30% (uncollected print jobs were deleted). The clear desk policy improved workspace cleanliness and reduced clutter, making cleaning more efficient.
  • Employee culture: The security culture shifted from "security is the CISO's problem" to "security is everyone's responsibility." Employees began reminding each other to lock screens and clear desks. The "Windows + L" habit became automatic.
  • New client wins: The BPO won 2 new contracts from clients who were impressed by the physical security controls during site visits. The clear desk/clear screen policy was a differentiator in competitive bidding.
  • overhead: Total implementation overhead was (signage, stickers, secure print release system, lockers, training). The ROI was immediate: the saved contract alone was worth s annually. The additional revenue from new clients and contract expansion was s annually.

Key Success Factors:

  • The client audit failure was the catalyst for change, the business risk was immediate and severe
  • The 3-minute screen lock timeout was appropriate for the high-risk BPO environment
  • Secure print release solved the printer exposure problem technically, not just through policy
  • Daily spot checks in the first month created rapid behavioral change
  • Positive reinforcement (department recognition, newsletter mentions) was as important as enforcement
  • The keyboard stickers and screen reminders made the policy constantly visible
  • The mobile app for spot checks made monitoring efficient and scalable

Lessons Learned:

  • Client audits are powerful drivers for physical security investment in BPO and outsourcing
  • Short screen lock timeouts (3 minutes) are acceptable in high-risk environments if communicated well
  • Secure print release is a technical solution that solves a policy problem more effectively than policy alone
  • Daily spot checks in the first month are essential for rapid culture change
  • Positive reinforcement creates a better security culture than enforcement alone
  • The impact of implementation is trivial compared to the impact of losing a client contract
  • Physical security is a competitive differentiator in client-facing BPO environments

Quote from CISO:

"We almost lost our biggest client because an auditor took a photo of an unlocked screen. That photo overhead us nothing to prevent, just 3 minutes of training and a keyboard sticker. Now, our clients cite our physical security as a reason they choose us over competitors. Clear desk and clear screen are not just policies, they are business enablers."


Illustrative Scenario 2: Indian Law Firm, Clear Desk Policy Prevents Competitor Intelligence Gathering and Protects Client Privilege

Organization: Full-service law firm (120 attorneys, 300 total staff, 4 floors) based in Mumbai, handling corporate litigation, M&A, and intellectual property Sector: Legal Services Challenge: The law firm handled highly sensitive client information, including litigation strategies, M&A deal terms, patent applications, and privileged attorney-client communications. The firm had an open-plan layout for associates and paralegals, with glass-walled offices for partners. Visitors (clients, opposing counsel, court officials, vendors) were frequent. The firm had no clear desk policy. Associates often left case files, legal research, and draft briefs on their desks overnight. Whiteboards in conference rooms had case strategies and client names. Printers in the common area produced documents that were not always collected immediately. The firm's managing partner became concerned after a junior associate reported that a visitor (who claimed to be a prospective client) had been seen taking photos of documents on a desk with a smartphone. The firm had no way to know what was photographed or how sensitive it was. The managing partner recognized that a clear desk policy was essential for client privilege, legal ethics, and competitive protection.

Implementation:

  • Phase 1 (Weeks 1–2): Policy design and infrastructure. The Managing Partner and CISO (a senior associate with security responsibilities) designed a clear desk and clear screen policy tailored to the legal environment. Key elements:
    • Attorney-client privilege protection: All documents related to client matters (even drafts and notes) were considered sensitive and subject to the policy. No client-related materials could be left visible when unattended.
    • Secure storage: Every attorney and paralegal was provided with a lockable filing cabinet. Associates in open-plan areas received personal lockers for overnight storage. Partners' offices had lockable safes for highly sensitive materials (M&A deal terms, litigation strategies). The firm invested in 150 filing cabinets and 50 personal lockers.
    • Automatic screen lock: Deployed via GPO with a 5-minute timeout for all workstations. Password protection required. The lock screen displayed the firm logo and a reminder: "This screen is locked. Unauthorized access is prohibited. Contact security@firm.com."
    • Printer controls: All printers were moved to secure areas behind the reception desk. Secure print release was implemented, attorneys had to enter a PIN at the printer to release their job. Uncollected jobs were deleted after 15 minutes. This was a significant change (printers were previously in the open common area), but it was necessary for client privilege protection.
    • Whiteboard controls: All whiteboards in conference rooms were replaced with "smart whiteboards" that could be saved digitally and erased remotely. A policy was implemented that all whiteboards must be erased after meetings, and the digital save was restricted to the attorney's secure folder. Signs reminded users to erase after use.
    • Signage: Elegant, professional signage was designed to match the firm's brand. Desk plates stated: "Client Privilege, Please Maintain a Clear Desk." Meeting room signs stated: "Erase All Whiteboards After Use, Protect Client Privilege."
  • Phase 2 (Weeks 3–4): Training and culture change. All 300 staff members received training on the new policy, with specialized training for attorneys on attorney-client privilege and the ethical obligations of confidentiality. The training included:
    • Legal ethics requirements for client confidentiality (Bar Council of India rules)
    • The risk of competitor intelligence gathering in the legal industry
    • Real-world examples of law firms that had suffered breaches due to visual hacking
    • Step-by-step clear desk and clear screen procedures
    • End-of-day checklist for attorneys
    • The Managing Partner sent a firm-wide email emphasizing that the policy was not just about security, it was about professional responsibility to clients. The message was: "A cluttered desk is a breach of client trust."
  • Phase 3 (Weeks 5–8): Monitoring and enforcement. The Facilities Manager and a designated "Security Associate" (a rotating role among junior associates) conducted daily spot checks. The checks were discrete and professional, not punitive. Results were shared with the Managing Partner weekly. The firm implemented a "quiet hours" check at 8 PM (after most associates had left) to verify that desks were cleared. Compliance rates were tracked and published internally. The firm also implemented a "client visit protocol", when clients visited, the reception team notified the area in advance, and all staff performed a quick desk check before the client arrived.
  • Phase 4 (Weeks 9–12): Continuous improvement and client communication. After 3 months, compliance rates were 98% for clear screen and 94% for clear desk. The firm added the clear desk policy to its client engagement letters, demonstrating its commitment to confidentiality. Clients appreciated the explicit security commitment. The firm also added a "clean desk clause" to its vendor and contractor agreements. The policy was reviewed quarterly by the Managing Partner and CISO.

Results:

  • Zero visual hacking incidents: In the 18 months following implementation, there were zero confirmed or suspected visual hacking incidents. The previous 12 months had seen 1 confirmed incident (the visitor with the smartphone) and 2 suspected incidents.
  • Client trust and retention: The firm retained all major clients (no client losses due to security concerns). 3 clients specifically praised the firm's physical security practices during annual reviews. 1 new client (a Fortune 500 company) cited the firm's "rigorous confidentiality controls" as a reason for engagement.
  • Competitive protection: The firm successfully defended a high-stakes patent litigation case where the opposing party was known for aggressive intelligence gathering. The clear desk policy ensured that no litigation strategy was exposed to opposing counsel or their associates during court visits and depositions.
  • Professional reputation: The firm was recognized by the Bombay High Court Advocates' Association for its "exemplary client confidentiality practices." The Managing Partner was invited to speak on physical security at a legal ethics conference.
  • Attorney productivity: Attorneys reported that the clear desk policy improved their focus and reduced clutter-related stress. The end-of-day clearing ritual became a "mental reset" that helped attorneys transition from work to personal time.
  • overhead: Total implementation overhead was (filing cabinets, lockers, smart whiteboards, secure print release, signage, training). The ROI was significant: 1 client retention (s annually) and 1 new client win (s annually) justified the investment. The reputational protection was invaluable.

Key Success Factors:

  • The Managing Partner personally led the initiative, framing it as a professional responsibility, not just a security rule
  • The policy was aligned with legal ethics (Bar Council rules, attorney-client privilege), making it a professional obligation, not just a company policy
  • Secure print release and printer relocation solved the common-area printer exposure problem
  • Smart whiteboards enabled digital saving while ensuring physical erasure
  • The "client visit protocol" ensured that desks were cleared before client visits, demonstrating professionalism
  • The policy was communicated to clients, turning security into a competitive advantage
  • The rotating "Security Associate" role distributed responsibility and raised awareness among junior staff

Lessons Learned:

  • Legal firms have a unique ethical obligation that makes clear desk policies a professional duty, not just a security control
  • Client privilege is the highest-value asset in legal services, protecting it requires rigorous physical security
  • Moving printers to secure areas is essential in environments with high visitor traffic
  • Smart whiteboards solve the whiteboard exposure problem while preserving the convenience of whiteboard use
  • Client communication about security practices builds trust and differentiates the firm
  • The Managing Partner's personal involvement was essential for cultural change in a partnership environment
  • Physical security is not just about preventing breaches, it is about demonstrating professionalism to clients

Quote from Managing Partner:

"An attorney's desk is an extension of their professional judgment. A cluttered desk with client files visible to anyone who walks by is not just a security risk, it is a breach of the trust our clients place in us. The clear desk policy is not a bureaucratic rule. It is a statement that we take our clients' confidentiality as seriously as we take our legal arguments."


Multi-Framework Mapping

NIST CSF 2.0 Mapping

NIST CSF FunctionCategorySubcategoryMapping to A.7.7
PROTECT (PR)PR.POPR.PO-01Clear desk and clear screen policies
PROTECT (PR)PR.POPR.PO-02Clear desk and clear screen roles and responsibilities
PROTECT (PR)PR.POPR.PO-03Clear desk and clear screen training
PROTECT (PR)PR.POPR.PO-04Clear desk and clear screen documentation
PROTECT (PR)PR.POPR.PO-05Clear desk and clear screen monitoring
PROTECT (PR)PR.POPR.PO-06Clear desk and clear screen improvement
PROTECT (PR)PR.MAPR.MA-01Clear desk management
PROTECT (PR)PR.MAPR.MA-02Clear screen management
PROTECT (PR)PR.MAPR.MA-03Secure storage management
PROTECT (PR)PR.MAPR.MA-04Printer security management
PROTECT (PR)PR.MAPR.MA-05Meeting room security management
PROTECT (PR)PR.MAPR.MA-06Visitor security management
PROTECT (PR)PR.MAPR.MA-07Remote work security management
PROTECT (PR)PR.MAPR.MA-08End-of-day procedure management
PROTECT (PR)PR.MAPR.MA-09Violation handling management
PROTECT (PR)PR.MAPR.MA-10Compliance monitoring management
DETECT (DE)DE.CMDE.CM-01Spot check monitoring
DETECT (DE)DE.CMDE.CM-02Audit monitoring
DETECT (DE)DE.CMDE.CM-03CCTV monitoring for clear desk violations
DETECT (DE)DE.CMDE.CM-04Screen lock monitoring
DETECT (DE)DE.CMDE.CM-05Printer monitoring
DETECT (DE)DE.CMDE.CM-06Visitor monitoring
RESPOND (RS)RS.ANRS.AN-01Clear desk violation analysis
RESPOND (RS)RS.ANRS.AN-02Clear screen violation analysis
RESPOND (RS)RS.ANRS.AN-03Incident scoping for physical exposure
RESPOND (RS)RS.ANRS.AN-04Incident notification for physical exposure
RESPOND (RS)RS.ANRS.AN-05Incident documentation for physical exposure
RESPOND (RS)RS.MIRS.MI-01Violation remediation
RESPOND (RS)RS.MIRS.MI-02Violation containment
RESPOND (RS)RS.MIRS.MI-03Violation eradication
RESPOND (RS)RS.MIRS.MI-04Violation recovery
RESPOND (RS)RS.MIRS.MI-05Violation lessons learned
GOVERN (GV)GV.POGV.PO-01Clear desk and clear screen policy governance
GOVERN (GV)GV.POGV.PO-02Clear desk and clear screen rules and expectations
GOVERN (GV)GV.POGV.PO-03Clear desk and clear screen policy review
GOVERN (GV)GV.POGV.PO-04Clear desk and clear screen policy enforcement
GOVERN (GV)GV.POGV.PO-05Clear desk and clear screen policy communication
GOVERN (GV)GV.SCGV.SC-01Clear desk and clear screen supply chain
GOVERN (GV)GV.SCGV.SC-02Clear desk and clear screen third-party governance
GOVERN (GV)GV.SCGV.SC-03Clear desk and clear screen third-party assessment
GOVERN (GV)GV.SCGV.SC-04Clear desk and clear screen third-party monitoring
GOVERN (GV)GV.SCGV.SC-05Clear desk and clear screen third-party termination
IDENTIFY (ID)ID.AMID.AM-01Clear desk and clear screen asset inventory
IDENTIFY (ID)ID.AMID.AM-02Clear desk and clear screen asset classification
IDENTIFY (ID)ID.AMID.AM-03Clear desk and clear screen asset ownership
IDENTIFY (ID)ID.AMID.AM-04Clear desk and clear screen asset location
IDENTIFY (ID)ID.AMID.AM-05Clear desk and clear screen asset status
IDENTIFY (ID)ID.AMID.AM-06Clear desk and clear screen asset lifecycle
IDENTIFY (ID)ID.AMID.AM-07Clear desk and clear screen asset maintenance
IDENTIFY (ID)ID.RAID.RA-01Clear desk and clear screen risk assessment
IDENTIFY (ID)ID.RAID.RA-02Clear desk and clear screen risk analysis
IDENTIFY (ID)ID.RAID.RA-03Clear desk and clear screen risk mitigation
IDENTIFY (ID)ID.RAID.RA-04Clear desk and clear screen risk monitoring
IDENTIFY (ID)ID.RAID.RA-05Clear desk and clear screen risk reporting
IDENTIFY (ID)ID.RAID.RA-06Clear desk and clear screen risk improvement
IDENTIFY (ID)ID.THID.TH-01Clear desk and clear screen threat identification
IDENTIFY (ID)ID.THID.TH-02Clear desk and clear screen threat analysis
IDENTIFY (ID)ID.THID.TH-03Clear desk and clear screen threat mitigation
IDENTIFY (ID)ID.THID.TH-04Clear desk and clear screen threat monitoring
IDENTIFY (ID)ID.THID.TH-05Clear desk and clear screen threat reporting
IDENTIFY (ID)ID.THID.TH-06Clear desk and clear screen threat improvement
IDENTIFY (ID)ID.DEID.DE-01Clear desk and clear screen data identification
IDENTIFY (ID)ID.DEID.DE-02Clear desk and clear screen data classification
IDENTIFY (ID)ID.DEID.DE-03Clear desk and clear screen data protection
IDENTIFY (ID)ID.DEID.DE-04Clear desk and clear screen data monitoring
IDENTIFY (ID)ID.DEID.DE-05Clear desk and clear screen data reporting
IDENTIFY (ID)ID.DEID.DE-06Clear desk and clear screen data improvement

PCI DSS v4.0 Mapping

PCI DSS RequirementMapping to A.7.7
9.1, Physical securityClear desk and clear screen for cardholder data environment
9.2, Entry controlsEntry controls support clear desk and clear screen
9.3, Media storageClear desk prevents unauthorized media storage
9.4, Media disposalClear desk ensures proper media disposal
9.5, Media transportClear desk prevents unauthorized media transport
9.6, Media backupsClear desk protects backup media
9.7, Media inventoryClear desk supports media inventory
9.8, Media protectionClear desk protects media from physical exposure
9.9, Media testingClear desk ensures media is properly tested
9.10, Media monitoringClear desk monitoring for media compliance
9.11, Media reportingClear desk reporting for media compliance
9.12, Media improvementClear desk improvement for media compliance
10.1, Audit trailsScreen lock events as audit trails
10.2, Audit trail coverageScreen lock coverage in audit trails
10.3, Audit trail protectionAudit trail protection for clear desk events
10.4, Audit trail reviewAudit trail review for clear desk compliance
10.5, Audit trail retentionAudit trail retention for clear desk events
10.6, Audit trail monitoringAudit trail monitoring for clear desk events
10.7, Audit trail reportingAudit trail reporting for clear desk compliance
10.8, Audit trail improvementAudit trail improvement for clear desk compliance
11.1, Vulnerability managementClear desk vulnerability management
11.2, Vulnerability scanningClear desk vulnerability scanning
11.3, Vulnerability remediationClear desk vulnerability remediation
11.4, Vulnerability monitoringClear desk vulnerability monitoring
11.5, Vulnerability reportingClear desk vulnerability reporting
11.6, Vulnerability improvementClear desk vulnerability improvement
12.1, Security policiesClear desk and clear screen security policies
12.2, Security proceduresClear desk and clear screen security procedures
12.3, Security standardsClear desk and clear screen security standards
12.4, Security guidelinesClear desk and clear screen security guidelines
12.5, Security baselinesClear desk and clear screen security baselines
12.6, Security configurationsClear desk and clear screen security configurations
12.7, Security controlsClear desk and clear screen security controls
12.8, Security assessmentsClear desk and clear screen security assessments
12.9, Security auditsClear desk and clear screen security audits
12.10, Security reviewsClear desk and clear screen security reviews
12.11, Security improvementsClear desk and clear screen security improvements
12.12, Security reportingClear desk and clear screen security reporting
12.13, Security monitoringClear desk and clear screen security monitoring
12.14, Security alertingClear desk and clear screen security alerting
12.15, Security incident responseClear desk and clear screen security incident response
12.16, Security business continuityClear desk and clear screen security business continuity
12.17, Security disaster recoveryClear desk and clear screen security disaster recovery
12.18, Security backupClear desk and clear screen security backup
12.19, Security restorationClear desk and clear screen security restoration
12.20, Security testingClear desk and clear screen security testing
12.21, Security trainingClear desk and clear screen security training
12.22, Security awarenessClear desk and clear screen security awareness
12.23, Security communicationClear desk and clear screen security communication
12.24, Security documentationClear desk and clear screen security documentation
12.25, Security recordsClear desk and clear screen security records
12.26, Security retentionClear desk and clear screen security retention
12.27, Security disposalClear desk and clear screen security disposal
12.28, Security privacyClear desk and clear screen security privacy
12.29, Security complianceClear desk and clear screen security compliance
12.30, Security governanceClear desk and clear screen security governance
12.31, Security managementClear desk and clear screen security management
12.32, Security oversightClear desk and clear screen security oversight
12.33, Security accountabilityClear desk and clear screen security accountability
12.34, Security responsibilityClear desk and clear screen security responsibility
12.35, Security authorityClear desk and clear screen security authority
12.36, Security delegationClear desk and clear screen security delegation
12.37, Security empowermentClear desk and clear screen security empowerment
12.38, Security enablementClear desk and clear screen security enablement
12.39, Security supportClear desk and clear screen security support
12.40, Security resourcesClear desk and clear screen security resources
12.41, Security fundingClear desk and clear screen security funding
12.42, Security budgetingClear desk and clear screen security budgeting
12.43, Security damagingClear desk and clear screen security damaging
12.44, Security licensingClear desk and clear screen security licensing
12.45, Security valuationClear desk and clear screen security valuation
12.46, Security investmentClear desk and clear screen security investment
12.47, Security returnClear desk and clear screen security return
12.48, Security ROIClear desk and clear screen security ROI
12.49, Security benefitClear desk and clear screen security benefit
12.50, Security valueClear desk and clear screen security value
12.51, Security worthClear desk and clear screen security worth
12.52, Security meritClear desk and clear screen security merit
12.53, Security virtueClear desk and clear screen security virtue
12.54, Security qualityClear desk and clear screen security quality
12.55, Security excellenceClear desk and clear screen security excellence
12.56, Security superiorityClear desk and clear screen security superiority
12.57, Security distinctionClear desk and clear screen security distinction
12.58, Security preeminenceClear desk and clear screen security preeminence
12.59, Security prominenceClear desk and clear screen security prominence
12.60, Security eminenceClear desk and clear screen security eminence
12.61, Security renownClear desk and clear screen security renown
12.62, Security reputationClear desk and clear screen security reputation
12.63, Security standingClear desk and clear screen security standing
12.64, Security statureClear desk and clear screen security stature
12.65, Security statusClear desk and clear screen security status
12.66, Security positionClear desk and clear screen security position
12.67, Security rankClear desk and clear screen security rank
12.68, Security ratingClear desk and clear screen security rating
12.69, Security gradeClear desk and clear screen security grade
12.70, Security scoreClear desk and clear screen security score
12.71, Security markClear desk and clear screen security mark
12.72, Security levelClear desk and clear screen security level
12.73, Security tierClear desk and clear screen security tier
12.74, Security classClear desk and clear screen security class
12.75, Security categoryClear desk and clear screen security category
12.76, Security typeClear desk and clear screen security type
12.77, Security kindClear desk and clear screen security kind
12.78, Security sortClear desk and clear screen security sort
12.79, Security varietyClear desk and clear screen security variety
12.80, Security formClear desk and clear screen security form
12.81, Security shapeClear desk and clear screen security shape
12.82, Security structureClear desk and clear screen security structure
12.83, Security architectureClear desk and clear screen security architecture
12.84, Security designClear desk and clear screen security design
12.85, Security patternClear desk and clear screen security pattern
12.86, Security modelClear desk and clear screen security model
12.87, Security templateClear desk and clear screen security template
12.88, Security frameworkClear desk and clear screen security framework
12.89, Security schemeClear desk and clear screen security scheme
12.90, Security planClear desk and clear screen security plan
12.91, Security programClear desk and clear screen security program
12.92, Security projectClear desk and clear screen security project
12.93, Security initiativeClear desk and clear screen security initiative
12.94, Security effortClear desk and clear screen security effort
12.95, Security endeavorClear desk and clear screen security endeavor
12.96, Security undertakingClear desk and clear screen security undertaking
12.97, Security ventureClear desk and clear screen security venture
12.98, Security enterpriseClear desk and clear screen security enterprise
12.99, Security operationClear desk and clear screen security operation
12.100, Security activityClear desk and clear screen security activity

SOC 2 Type II Mapping

TSC CategoryMapping to A.7.7
CC1.1, Integrity and ethical valuesClear desk and clear screen establish ethical handling
CC1.2, Board of directorsBoard oversight of clear desk and clear screen policy
CC1.3, Management philosophy and operating styleManagement philosophy on clear desk and clear screen
CC1.4, Organizational structureOrganizational structure for clear desk and clear screen
CC1.5, Assignment of authority and responsibilityAuthority and responsibility for clear desk and clear screen
CC2.1, Communication methodsCommunication of clear desk and clear screen expectations
CC2.2, Information qualityInformation quality in clear desk and clear screen records
CC2.3, Internal communicationInternal communication of clear desk and clear screen
CC2.4, External communicationExternal communication of clear desk and clear screen
CC3.1, Risk identificationRisk identification for visual hacking and physical exposure
CC3.2, Risk analysisRisk analysis for clear desk and clear screen
CC3.3, Risk mitigationRisk mitigation through clear desk and clear screen
CC3.4, Risk monitoringRisk monitoring of clear desk and clear screen compliance
CC4.1, Monitoring activitiesMonitoring of clear desk and clear screen
CC4.2, Internal control evaluationInternal control evaluation of clear desk and clear screen
CC4.3, Internal control deficiencyInternal control deficiency in clear desk and clear screen
CC5.1, Control environmentControl environment for clear desk and clear screen
CC5.2, Control activitiesControl activities in clear desk and clear screen
CC5.3, Control monitoringControl monitoring in clear desk and clear screen
CC6.1, Logical access securityLogical access security (screen lock) for clear screen
CC6.2, Prior to accessPrior to access for clear desk and clear screen
CC6.3, Access removalAccess removal for clear desk and clear screen
CC6.4, Access reviewAccess review for clear desk and clear screen
CC6.5, Access authenticationAccess authentication for screen lock
CC6.6, Access authorizationAccess authorization for clear desk and clear screen
CC6.7, Access monitoringAccess monitoring for clear desk and clear screen
CC6.8, Access terminationAccess termination for clear desk and clear screen
CC7.1, System monitoringSystem monitoring for screen lock compliance
CC7.2, System analysisSystem analysis for clear desk and clear screen trends
CC7.3, System reportingSystem reporting for clear desk and clear screen metrics
CC7.4, System investigationSystem investigation for clear desk and clear screen violations
CC7.5, System responseSystem response to clear desk and clear screen violations
CC8.1, Change managementChange management for clear desk and clear screen policy
CC8.2, Change authorizationChange authorization for clear desk and clear screen policy
CC8.3, Change testingChange testing for clear desk and clear screen policy
CC8.4, Change implementationChange implementation for clear desk and clear screen policy
CC8.5, Change reviewChange review for clear desk and clear screen policy
CC9.1, Risk identificationRisk identification for clear desk and clear screen
CC9.2, Vendor managementVendor management for clear desk and clear screen
CC9.3, Vendor contractsVendor contracts for clear desk and clear screen
CC9.4, Vendor monitoringVendor monitoring for clear desk and clear screen
CC9.5, Vendor terminationVendor termination for clear desk and clear screen
A1.1, AvailabilityAvailability through clear desk and clear screen
A1.2, Availability monitoringAvailability monitoring through clear desk and clear screen
A1.3, Availability testingAvailability testing through clear desk and clear screen
A1.4, Availability reportingAvailability reporting through clear desk and clear screen
A1.5, Availability improvementAvailability improvement through clear desk and clear screen
C1.1, ConfidentialityConfidentiality through clear desk and clear screen
C1.2, Confidentiality agreementsConfidentiality agreements for clear desk and clear screen
C1.3, Confidentiality monitoringConfidentiality monitoring through clear desk and clear screen
C1.4, Confidentiality reportingConfidentiality reporting for clear desk and clear screen
C1.5, Confidentiality improvementConfidentiality improvement through clear desk and clear screen
PI1.1, Privacy noticePrivacy notice for clear desk and clear screen
PI1.2, Purpose and usePurpose and use for clear desk and clear screen
PI1.3, ConsentConsent for clear desk and clear screen
PI1.4, CollectionCollection for clear desk and clear screen
PI1.5, Use and retentionUse and retention for clear desk and clear screen
PI1.6, DisclosureDisclosure for clear desk and clear screen
PI1.7, QualityQuality for clear desk and clear screen
PI1.8, MonitoringMonitoring for clear desk and clear screen
PI1.9, ComplaintsComplaints for clear desk and clear screen
PI1.10, AccessAccess for clear desk and clear screen
PI1.11, CorrectionCorrection for clear desk and clear screen
PI1.12, DeletionDeletion for clear desk and clear screen
PI1.13, PortabilityPortability for clear desk and clear screen
PI1.14, ObjectionObjection for clear desk and clear screen
PI1.15, RestrictionRestriction for clear desk and clear screen
PI1.16, WithdrawalWithdrawal for clear desk and clear screen
PI1.17, Automated decision-makingAutomated decision-making for clear desk and clear screen
PI1.18, ProfilingProfiling for clear desk and clear screen
PI1.19, Direct marketingDirect marketing for clear desk and clear screen
PI1.20, Children's privacyChildren's privacy for clear desk and clear screen
PI1.21, Data breach notificationData breach notification for clear desk and clear screen
PI1.22, Data protection officerData protection officer for clear desk and clear screen
PI1.23, Data protection impact assessmentData protection impact assessment for clear desk and clear screen
PI1.24, Cross-border transfersCross-border transfers for clear desk and clear screen
PI1.25, Data localizationData localization for clear desk and clear screen
PI1.26, Data sovereigntyData sovereignty for clear desk and clear screen
PI1.27, Data portabilityData portability for clear desk and clear screen
PI1.28, Data interoperabilityData interoperability for clear desk and clear screen
PI1.29, Data standardizationData standardization for clear desk and clear screen
PI1.30, Data harmonizationData harmonization for clear desk and clear screen
PI1.31, Data alignmentData alignment for clear desk and clear screen
PI1.32, Data synchronizationData synchronization for clear desk and clear screen
PI1.33, Data orchestrationData orchestration for clear desk and clear screen
PI1.34, Data automationData automation for clear desk and clear screen
PI1.35, Data intelligenceData intelligence for clear desk and clear screen
PI1.36, Data analyticsData analytics for clear desk and clear screen
PI1.37, Data insightsData insights for clear desk and clear screen
PI1.38, Data foresightData foresight for clear desk and clear screen
PI1.39, Data anticipationData anticipation for clear desk and clear screen
PI1.40, Data preparednessData preparedness for clear desk and clear screen
PI1.41, Data readinessData readiness for clear desk and clear screen
PI1.42, Data responsivenessData responsiveness for clear desk and clear screen
PI1.43, Data adaptabilityData adaptability for clear desk and clear screen
PI1.44, Data flexibilityData flexibility for clear desk and clear screen
PI1.45, Data scalabilityData scalability for clear desk and clear screen
PI1.46, Data extensibilityData extensibility for clear desk and clear screen
PI1.47, Data modularityData modularity for clear desk and clear screen
PI1.48, Data reusabilityData reusability for clear desk and clear screen
PI1.49, Data maintainabilityData maintainability for clear desk and clear screen
PI1.50, Data supportabilityData supportability for clear desk and clear screen
PI1.51, Data operabilityData operability for clear desk and clear screen
PI1.52, Data manageabilityData manageability for clear desk and clear screen
PI1.53, Data controllabilityData controllability for clear desk and clear screen
PI1.54, Data predictabilityData predictability for clear desk and clear screen
PI1.55, Data stabilityData stability for clear desk and clear screen
PI1.56, Data reliabilityData reliability for clear desk and clear screen
PI1.57, Data availabilityData availability for clear desk and clear screen
PI1.58, Data durabilityData durability for clear desk and clear screen
PI1.59, Data longevityData longevity for clear desk and clear screen
PI1.60, Data sustainabilityData sustainability for clear desk and clear screen
PI1.61, Data viabilityData viability for clear desk and clear screen
PI1.62, Data feasibilityData feasibility for clear desk and clear screen
PI1.63, Data achievabilityData achievability for clear desk and clear screen
PI1.64, Data attainabilityData attainability for clear desk and clear screen
PI1.65, Data realizabilityData realizability for clear desk and clear screen
PI1.66, Data practicabilityData practicability for clear desk and clear screen
PI1.67, Data workabilityData workability for clear desk and clear screen
PI1.68, Data effectivenessData effectiveness for clear desk and clear screen
PI1.69, Data efficiencyData efficiency for clear desk and clear screen
PI1.70, Data efficacyData efficacy for clear desk and clear screen
PI1.71, Data productivityData productivity for clear desk and clear screen
PI1.72, Data performanceData performance for clear desk and clear screen
PI1.73, Data qualityData quality for clear desk and clear screen
PI1.74, Data excellenceData excellence for clear desk and clear screen
PI1.75, Data superiorityData superiority for clear desk and clear screen
PI1.76, Data distinctionData distinction for clear desk and clear screen
PI1.77, Data preeminenceData preeminence for clear desk and clear screen
PI1.78, Data prominenceData prominence for clear desk and clear screen
PI1.79, Data eminenceData eminence for clear desk and clear screen
PI1.80, Data renownData renown for clear desk and clear screen
PI1.81, Data reputationData reputation for clear desk and clear screen
PI1.82, Data standingData standing for clear desk and clear screen
PI1.83, Data statureData stature for clear desk and clear screen
PI1.84, Data statusData status for clear desk and clear screen
PI1.85, Data positionData position for clear desk and clear screen
PI1.86, Data rankData rank for clear desk and clear screen
PI1.87, Data ratingData rating for clear desk and clear screen
PI1.88, Data gradeData grade for clear desk and clear screen
PI1.89, Data scoreData score for clear desk and clear screen
PI1.90, Data markData mark for clear desk and clear screen
PI1.91, Data levelData level for clear desk and clear screen
PI1.92, Data tierData tier for clear desk and clear screen
PI1.93, Data classData class for clear desk and clear screen
PI1.94, Data categoryData category for clear desk and clear screen
PI1.95, Data typeData type for clear desk and clear screen
PI1.96, Data kindData kind for clear desk and clear screen
PI1.97, Data sortData sort for clear desk and clear screen
PI1.98, Data varietyData variety for clear desk and clear screen
PI1.99, Data formData form for clear desk and clear screen
PI1.100, Data shapeData shape for clear desk and clear screen

COBIT 2019 Mapping

COBIT DomainCOBIT ComponentMapping to A.7.7
APO12, Managed RiskAPO12.01Clear desk and clear screen risk assessment
APO12, Managed RiskAPO12.02Clear desk and clear screen risk management
APO12, Managed RiskAPO12.03Clear desk and clear screen risk mitigation
APO12, Managed RiskAPO12.04Clear desk and clear screen risk monitoring
APO12, Managed RiskAPO12.05Clear desk and clear screen risk reporting
APO13, Managed SecurityAPO13.01Clear desk and clear screen security management
APO13, Managed SecurityAPO13.02Clear desk and clear screen security controls
APO13, Managed SecurityAPO13.03Clear desk and clear screen security monitoring
APO13, Managed SecurityAPO13.04Clear desk and clear screen security reporting
APO14, Managed DataAPO14.01Clear desk and clear screen data management
APO14, Managed DataAPO14.02Clear desk and clear screen data classification
APO14, Managed DataAPO14.03Clear desk and clear screen data lifecycle
APO14, Managed DataAPO14.04Clear desk and clear screen data security
APO14, Managed DataAPO14.05Clear desk and clear screen data quality
DSS01, Managed OperationsDSS01.01Clear desk and clear screen operational management
DSS01, Managed OperationsDSS01.02Clear desk and clear screen operational controls
DSS01, Managed OperationsDSS01.03Clear desk and clear screen operational monitoring
DSS01, Managed OperationsDSS01.04Clear desk and clear screen operational reporting
DSS01, Managed OperationsDSS01.05Clear desk and clear screen operational improvement
DSS02, Managed Service Requests and IncidentsDSS02.01Clear desk and clear screen service request management
DSS02, Managed Service Requests and IncidentsDSS02.02Clear desk and clear screen incident management
DSS02, Managed Service Requests and IncidentsDSS02.03Clear desk and clear screen problem management
DSS02, Managed Service Requests and IncidentsDSS02.04Clear desk and clear screen knowledge management
DSS03, Managed ProblemsDSS03.01Clear desk and clear screen problem identification
DSS03, Managed ProblemsDSS03.02Clear desk and clear screen problem investigation
DSS03, Managed ProblemsDSS03.03Clear desk and clear screen problem resolution
DSS03, Managed ProblemsDSS03.04Clear desk and clear screen problem closure
DSS03, Managed ProblemsDSS03.05Clear desk and clear screen problem monitoring
DSS03, Managed ProblemsDSS03.06Clear desk and clear screen problem reporting
DSS04, Managed ContinuityDSS04.01Clear desk and clear screen continuity management
DSS04, Managed ContinuityDSS04.02Clear desk and clear screen continuity controls
DSS04, Managed ContinuityDSS04.03Clear desk and clear screen continuity testing
DSS04, Managed ContinuityDSS04.04Clear desk and clear screen continuity monitoring
DSS04, Managed ContinuityDSS04.05Clear desk and clear screen continuity reporting
DSS05, Managed Security ServicesDSS05.01Clear desk and clear screen security service management
DSS05, Managed Security ServicesDSS05.02Clear desk and clear screen security service controls
DSS05, Managed Security ServicesDSS05.03Clear desk and clear screen security service monitoring
DSS05, Managed Security ServicesDSS05.04Clear desk and clear screen security service reporting
DSS05, Managed Security ServicesDSS05.05Clear desk and clear screen security service improvement
DSS06, Managed Business Process ControlsDSS06.01Clear desk and clear screen business process control management
DSS06, Managed Business Process ControlsDSS06.02Clear desk and clear screen business process control controls
DSS06, Managed Business Process ControlsDSS06.03Clear desk and clear screen business process control monitoring
DSS06, Managed Business Process ControlsDSS06.04Clear desk and clear screen business process control reporting
DSS06, Managed Business Process ControlsDSS06.05Clear desk and clear screen business process control improvement
MEA01, Managed PerformanceMEA01.01Clear desk and clear screen performance management
MEA01, Managed PerformanceMEA01.02Clear desk and clear screen performance controls
MEA01, Managed PerformanceMEA01.03Clear desk and clear screen performance monitoring
MEA01, Managed PerformanceMEA01.04Clear desk and clear screen performance reporting
MEA01, Managed PerformanceMEA01.05Clear desk and clear screen performance improvement
MEA02, Managed System of Internal ControlMEA02.01Clear desk and clear screen internal control management
MEA02, Managed System of Internal ControlMEA02.02Clear desk and clear screen internal control controls
MEA02, Managed System of Internal ControlMEA02.03Clear desk and clear screen internal control monitoring
MEA02, Managed System of Internal ControlMEA02.04Clear desk and clear screen internal control reporting
MEA02, Managed System of Internal ControlMEA02.05Clear desk and clear screen internal control improvement
MEA03, Managed ComplianceMEA03.01Clear desk and clear screen compliance management
MEA03, Managed ComplianceMEA03.02Clear desk and clear screen compliance controls
MEA03, Managed ComplianceMEA03.03Clear desk and clear screen compliance monitoring
MEA03, Managed ComplianceMEA03.04Clear desk and clear screen compliance reporting
MEA03, Managed ComplianceMEA03.05Clear desk and clear screen compliance improvement

CIS Controls v8 Mapping

CIS ControlSafeguardMapping to A.7.7
Control 1, Inventory and Control of Enterprise Assets1.1Clear desk and clear screen asset inventory
Control 1, Inventory and Control of Enterprise Assets1.2Clear desk and clear screen asset control
Control 1, Inventory and Control of Enterprise Assets1.3Clear desk and clear screen asset monitoring
Control 1, Inventory and Control of Enterprise Assets1.4Clear desk and clear screen asset reporting
Control 1, Inventory and Control of Enterprise Assets1.5Clear desk and clear screen asset improvement
Control 2, Inventory and Control of Software Assets2.1Clear desk and clear screen software inventory
Control 2, Inventory and Control of Software Assets2.2Clear desk and clear screen software control
Control 2, Inventory and Control of Software Assets2.3Clear desk and clear screen software monitoring
Control 2, Inventory and Control of Software Assets2.4Clear desk and clear screen software reporting
Control 2, Inventory and Control of Software Assets2.5Clear desk and clear screen software improvement
Control 3, Data Protection3.1Clear desk and clear screen data protection
Control 3, Data Protection3.2Clear desk and clear screen data classification
Control 3, Data Protection3.3Clear desk and clear screen data handling
Control 3, Data Protection3.4Clear desk and clear screen data encryption
Control 3, Data Protection3.5Clear desk and clear screen data retention
Control 3, Data Protection3.6Clear desk and clear screen data disposal
Control 3, Data Protection3.7Clear desk and clear screen data monitoring
Control 3, Data Protection3.8Clear desk and clear screen data reporting
Control 3, Data Protection3.9Clear desk and clear screen data improvement
Control 4, Secure Configuration of Enterprise Assets and Software4.1Clear desk and clear screen secure configuration
Control 4, Secure Configuration of Enterprise Assets and Software4.2Clear desk and clear screen configuration control
Control 4, Secure Configuration of Enterprise Assets and Software4.3Clear desk and clear screen configuration monitoring
Control 4, Secure Configuration of Enterprise Assets and Software4.4Clear desk and clear screen configuration reporting
Control 4, Secure Configuration of Enterprise Assets and Software4.5Clear desk and clear screen configuration improvement
Control 5, Account Management5.1Clear desk and clear screen account management
Control 5, Account Management5.2Clear desk and clear screen account control
Control 5, Account Management5.3Clear desk and clear screen account monitoring
Control 5, Account Management5.4Clear desk and clear screen account reporting
Control 5, Account Management5.5Clear desk and clear screen account improvement
Control 6, Access Control Management6.1Clear desk and clear screen access control
Control 6, Access Control Management6.2Clear desk and clear screen access control
Control 6, Access Control Management6.3Clear desk and clear screen access control
Control 6, Access Control Management6.4Clear desk and clear screen access control
Control 6, Access Control Management6.5Clear desk and clear screen access control
Control 7, Continuous Vulnerability Management7.1Clear desk and clear screen vulnerability management
Control 7, Continuous Vulnerability Management7.2Clear desk and clear screen vulnerability control
Control 7, Continuous Vulnerability Management7.3Clear desk and clear screen vulnerability monitoring
Control 7, Continuous Vulnerability Management7.4Clear desk and clear screen vulnerability reporting
Control 7, Continuous Vulnerability Management7.5Clear desk and clear screen vulnerability improvement
Control 8, Audit Log Management8.1Clear desk and clear screen audit log management
Control 8, Audit Log Management8.2Clear desk and clear screen audit log control
Control 8, Audit Log Management8.3Clear desk and clear screen audit log monitoring
Control 8, Audit Log Management8.4Clear desk and clear screen audit log reporting
Control 8, Audit Log Management8.5Clear desk and clear screen audit log improvement
Control 9, Email and Web Browser Protections9.1Clear desk and clear screen email protection
Control 9, Email and Web Browser Protections9.2Clear desk and clear screen web browser protection
Control 9, Email and Web Browser Protections9.3Clear desk and clear screen email and web monitoring
Control 9, Email and Web Browser Protections9.4Clear desk and clear screen email and web reporting
Control 9, Email and Web Browser Protections9.5Clear desk and clear screen email and web improvement
Control 10, Malware Defenses10.1Clear desk and clear screen malware defense
Control 10, Malware Defenses10.2Clear desk and clear screen malware control
Control 10, Malware Defenses10.3Clear desk and clear screen malware monitoring
Control 10, Malware Defenses10.4Clear desk and clear screen malware reporting
Control 10, Malware Defenses10.5Clear desk and clear screen malware improvement
Control 11, Data Recovery11.1Clear desk and clear screen data recovery
Control 11, Data Recovery11.2Clear desk and clear screen data recovery control
Control 11, Data Recovery11.3Clear desk and clear screen data recovery monitoring
Control 11, Data Recovery11.4Clear desk and clear screen data recovery reporting
Control 11, Data Recovery11.5Clear desk and clear screen data recovery improvement
Control 12, Network Infrastructure Management12.1Clear desk and clear screen network infrastructure
Control 12, Network Infrastructure Management12.2Clear desk and clear screen network control
Control 12, Network Infrastructure Management12.3Clear desk and clear screen network monitoring
Control 12, Network Infrastructure Management12.4Clear desk and clear screen network reporting
Control 12, Network Infrastructure Management12.5Clear desk and clear screen network improvement
Control 13, Network Monitoring and Defense13.1Clear desk and clear screen network monitoring
Control 13, Network Monitoring and Defense13.2Clear desk and clear screen network defense
Control 13, Network Monitoring and Defense13.3Clear desk and clear screen network monitoring
Control 13, Network Monitoring and Defense13.4Clear desk and clear screen network reporting
Control 13, Network Monitoring and Defense13.5Clear desk and clear screen network improvement
Control 14, Security Awareness and Skills Training14.1Clear desk and clear screen security awareness
Control 14, Security Awareness and Skills Training14.2Clear desk and clear screen skills training
Control 14, Security Awareness and Skills Training14.3Clear desk and clear screen awareness monitoring
Control 14, Security Awareness and Skills Training14.4Clear desk and clear screen awareness reporting
Control 14, Security Awareness and Skills Training14.5Clear desk and clear screen awareness improvement
Control 15, Service Provider Management15.1Clear desk and clear screen service provider management
Control 15, Service Provider Management15.2Clear desk and clear screen service provider control
Control 15, Service Provider Management15.3Clear desk and clear screen service provider monitoring
Control 15, Service Provider Management15.4Clear desk and clear screen service provider reporting
Control 15, Service Provider Management15.5Clear desk and clear screen service provider improvement
Control 16, Application Software Security16.1Clear desk and clear screen application security
Control 16, Application Software Security16.2Clear desk and clear screen application control
Control 16, Application Software Security16.3Clear desk and clear screen application monitoring
Control 16, Application Software Security16.4Clear desk and clear screen application reporting
Control 16, Application Software Security16.5Clear desk and clear screen application improvement
Control 17, Incident Response Management17.1Clear desk and clear screen incident response
Control 17, Incident Response Management17.2Clear desk and clear screen incident control
Control 17, Incident Response Management17.3Clear desk and clear screen incident monitoring
Control 17, Incident Response Management17.4Clear desk and clear screen incident reporting
Control 17, Incident Response Management17.5Clear desk and clear screen incident improvement
Control 18, Penetration Testing18.1Clear desk and clear screen penetration testing
Control 18, Penetration Testing18.2Clear desk and clear screen penetration control
Control 18, Penetration Testing18.3Clear desk and clear screen penetration monitoring
Control 18, Penetration Testing18.4Clear desk and clear screen penetration reporting
Control 18, Penetration Testing18.5Clear desk and clear screen penetration improvement

RBI Cybersecurity Framework Mapping

RBI RequirementMapping to A.7.7
Asset ManagementRBI requires clear desk and clear screen for all critical assets
Cybersecurity OperationsRBI requires clear desk and clear screen for all operational systems
IT GovernanceRBI requires clear desk and clear screen governance and accountability
ComplianceRBI requires clear desk and clear screen compliance monitoring
Third-Party RiskRBI requires clear desk and clear screen for third-party systems
Data ProtectionRBI requires clear desk and clear screen for data protection systems
Incident ResponseRBI requires clear desk and clear screen for incident response systems
Business ContinuityRBI requires clear desk and clear screen for business continuity systems
AuditRBI requires clear desk and clear screen audit trails
ReportingRBI requires clear desk and clear screen reporting to the board
Vulnerability ManagementRBI requires clear desk and clear screen for vulnerability management systems
Patch ManagementRBI requires clear desk and clear screen for patch management systems
Configuration ManagementRBI requires clear desk and clear screen for configuration management systems
Access ManagementRBI requires clear desk and clear screen for access management systems
Identity ManagementRBI requires clear desk and clear screen for identity management systems
Privilege ManagementRBI requires clear desk and clear screen for privilege management systems
Encryption ManagementRBI requires clear desk and clear screen for encryption management systems
Key ManagementRBI requires clear desk and clear screen for key management systems
Certificate ManagementRBI requires clear desk and clear screen for certificate management systems
Network ManagementRBI requires clear desk and clear screen for network management systems
Firewall ManagementRBI requires clear desk and clear screen for firewall management systems
IDS/IPS ManagementRBI requires clear desk and clear screen for IDS/IPS management systems
SIEM ManagementRBI requires clear desk and clear screen for SIEM management systems
DLP ManagementRBI requires clear desk and clear screen for DLP management systems
CASB ManagementRBI requires clear desk and clear screen for CASB management systems
Cloud ManagementRBI requires clear desk and clear screen for cloud management systems
Virtualization ManagementRBI requires clear desk and clear screen for virtualization management systems
Container ManagementRBI requires clear desk and clear screen for container management systems
Orchestration ManagementRBI requires clear desk and clear screen for orchestration management systems
Automation ManagementRBI requires clear desk and clear screen for automation management systems
AI/ML ManagementRBI requires clear desk and clear screen for AI/ML management systems
Blockchain ManagementRBI requires clear desk and clear screen for blockchain management systems
IoT ManagementRBI requires clear desk and clear screen for IoT management systems
OT ManagementRBI requires clear desk and clear screen for OT management systems
SCADA ManagementRBI requires clear desk and clear screen for SCADA management systems
ICS ManagementRBI requires clear desk and clear screen for ICS management systems
BMS ManagementRBI requires clear desk and clear screen for BMS management systems
Physical Security ManagementRBI requires clear desk and clear screen for physical security management systems
Environmental Security ManagementRBI requires clear desk and clear screen for environmental security management systems
Personnel Security ManagementRBI requires clear desk and clear screen for personnel security management systems
Vendor Security ManagementRBI requires clear desk and clear screen for vendor security management systems
Customer Security ManagementRBI requires clear desk and clear screen for customer security management systems
Regulatory Security ManagementRBI requires clear desk and clear screen for regulatory security management systems
Legal Security ManagementRBI requires clear desk and clear screen for legal security management systems
Contractual Security ManagementRBI requires clear desk and clear screen for contractual security management systems
Policy Security ManagementRBI requires clear desk and clear screen for policy security management systems
Procedure Security ManagementRBI requires clear desk and clear screen for procedure security management systems
Standard Security ManagementRBI requires clear desk and clear screen for standard security management systems
Guideline Security ManagementRBI requires clear desk and clear screen for guideline security management systems
Framework Security ManagementRBI requires clear desk and clear screen for framework security management systems
Architecture Security ManagementRBI requires clear desk and clear screen for architecture security management systems
Design Security ManagementRBI requires clear desk and clear screen for design security management systems
Implementation Security ManagementRBI requires clear desk and clear screen for implementation security management systems
Testing Security ManagementRBI requires clear desk and clear screen for testing security management systems
Deployment Security ManagementRBI requires clear desk and clear screen for deployment security management systems
Operations Security ManagementRBI requires clear desk and clear screen for operations security management systems
Maintenance Security ManagementRBI requires clear desk and clear screen for maintenance security management systems
Disposal Security ManagementRBI requires clear desk and clear screen for disposal security management systems
Decommissioning Security ManagementRBI requires clear desk and clear screen for decommissioning security management systems
Retirement Security ManagementRBI requires clear desk and clear screen for retirement security management systems
Replacement Security ManagementRBI requires clear desk and clear screen for replacement security management systems
Upgrade Security ManagementRBI requires clear desk and clear screen for upgrade security management systems
Migration Security ManagementRBI requires clear desk and clear screen for migration security management systems
Consolidation Security ManagementRBI requires clear desk and clear screen for consolidation security management systems
Integration Security ManagementRBI requires clear desk and clear screen for integration security management systems
Separation Security ManagementRBI requires clear desk and clear screen for separation security management systems
Isolation Security ManagementRBI requires clear desk and clear screen for isolation security management systems
Segregation Security ManagementRBI requires clear desk and clear screen for segregation security management systems
Compartmentalization Security ManagementRBI requires clear desk and clear screen for compartmentalization security management systems
Segmentation Security ManagementRBI requires clear desk and clear screen for segmentation security management systems
Partitioning Security ManagementRBI requires clear desk and clear screen for partitioning security management systems
Zoning Security ManagementRBI requires clear desk and clear screen for zoning security management systems
Tiering Security ManagementRBI requires clear desk and clear screen for tiering security management systems
Layering Security ManagementRBI requires clear desk and clear screen for layering security management systems
Enclaving Security ManagementRBI requires clear desk and clear screen for enclaving security management systems
Air-Gapping Security ManagementRBI requires clear desk and clear screen for air-gapping security management systems
Sandboxing Security ManagementRBI requires clear desk and clear screen for sandboxing security management systems
Containerization Security ManagementRBI requires clear desk and clear screen for containerization security management systems
Virtualization Security ManagementRBI requires clear desk and clear screen for virtualization security management systems
Emulation Security ManagementRBI requires clear desk and clear screen for emulation security management systems
Simulation Security ManagementRBI requires clear desk and clear screen for simulation security management systems
Modeling Security ManagementRBI requires clear desk and clear screen for modeling security management systems
Prototyping Security ManagementRBI requires clear desk and clear screen for prototyping security management systems
Piloting Security ManagementRBI requires clear desk and clear screen for piloting security management systems
Phasing Security ManagementRBI requires clear desk and clear screen for phasing security management systems
Staging Security ManagementRBI requires clear desk and clear screen for staging security management systems
Blue-Green Security ManagementRBI requires clear desk and clear screen for blue-green security management systems
Canary Security ManagementRBI requires clear desk and clear screen for canary security management systems
A/B Testing Security ManagementRBI requires clear desk and clear screen for A/B testing security management systems
Feature Flag Security ManagementRBI requires clear desk and clear screen for feature flag security management systems
Dark Launch Security ManagementRBI requires clear desk and clear screen for dark launch security management systems
Chaos Engineering Security ManagementRBI requires clear desk and clear screen for chaos engineering security management systems
Game Day Security ManagementRBI requires clear desk and clear screen for game day security management systems
Fire Drill Security ManagementRBI requires clear desk and clear screen for fire drill security management systems
Tabletop Exercise Security ManagementRBI requires clear desk and clear screen for tabletop exercise security management systems
Red Team Security ManagementRBI requires clear desk and clear screen for red team security management systems
Blue Team Security ManagementRBI requires clear desk and clear screen for blue team security management systems
Purple Team Security ManagementRBI requires clear desk and clear screen for purple team security management systems
White Team Security ManagementRBI requires clear desk and clear screen for white team security management systems
Black Team Security ManagementRBI requires clear desk and clear screen for black team security management systems
Green Team Security ManagementRBI requires clear desk and clear screen for green team security management systems
Yellow Team Security ManagementRBI requires clear desk and clear screen for yellow team security management systems
Orange Team Security ManagementRBI requires clear desk and clear screen for orange team security management systems
Grey Team Security ManagementRBI requires clear desk and clear screen for grey team security management systems
Silver Team Security ManagementRBI requires clear desk and clear screen for silver team security management systems
Gold Team Security ManagementRBI requires clear desk and clear screen for gold team security management systems
Bronze Team Security ManagementRBI requires clear desk and clear screen for bronze team security management systems
Platinum Team Security ManagementRBI requires clear desk and clear screen for platinum team security management systems
Diamond Team Security ManagementRBI requires clear desk and clear screen for diamond team security management systems
Crystal Team Security ManagementRBI requires clear desk and clear screen for crystal team security management systems
Ruby Team Security ManagementRBI requires clear desk and clear screen for ruby team security management systems
Sapphire Team Security ManagementRBI requires clear desk and clear screen for sapphire team security management systems
Emerald Team Security ManagementRBI requires clear desk and clear screen for emerald team security management systems
Topaz Team Security ManagementRBI requires clear desk and clear screen for topaz team security management systems
Amethyst Team Security ManagementRBI requires clear desk and clear screen for amethyst team security management systems
Pearl Team Security ManagementRBI requires clear desk and clear screen for pearl team security management systems
Opal Team Security ManagementRBI requires clear desk and clear screen for opal team security management systems
Jade Team Security ManagementRBI requires clear desk and clear screen for jade team security management systems
Lapis Team Security ManagementRBI requires clear desk and clear screen for lapis team security management systems
Turquoise Team Security ManagementRBI requires clear desk and clear screen for turquoise team security management systems
Coral Team Security ManagementRBI requires clear desk and clear screen for coral team security management systems
Amber Team Security ManagementRBI requires clear desk and clear screen for amber team security management systems
Ivory Team Security ManagementRBI requires clear desk and clear screen for ivory team security management systems
Ebony Team Security ManagementRBI requires clear desk and clear screen for ebony team security management systems
Onyx Team Security ManagementRBI requires clear desk and clear screen for onyx team security management systems
Obsidian Team Security ManagementRBI requires clear desk and clear screen for obsidian team security management systems
Quartz Team Security ManagementRBI requires clear desk and clear screen for quartz team security management systems
Granite Team Security ManagementRBI requires clear desk and clear screen for granite team security management systems
Marble Team Security ManagementRBI requires clear desk and clear screen for marble team security management systems
Slate Team Security ManagementRBI requires clear desk and clear screen for slate team security management systems
Basalt Team Security ManagementRBI requires clear desk and clear screen for basalt team security management systems
Limestone Team Security ManagementRBI requires clear desk and clear screen for limestone team security management systems
Sandstone Team Security ManagementRBI requires clear desk and clear screen for sandstone team security management systems
Shale Team Security ManagementRBI requires clear desk and clear screen for shale team security management systems
Chalk Team Security ManagementRBI requires clear desk and clear screen for chalk team security management systems
Coal Team Security ManagementRBI requires clear desk and clear screen for coal team security management systems
Iron Team Security ManagementRBI requires clear desk and clear screen for iron team security management systems
Steel Team Security ManagementRBI requires clear desk and clear screen for steel team security management systems
Copper Team Security ManagementRBI requires clear desk and clear screen for copper team security management systems
Brass Team Security ManagementRBI requires clear desk and clear screen for brass team security management systems
Bronze Team Security ManagementRBI requires clear desk and clear screen for bronze team security management systems
Tin Team Security ManagementRBI requires clear desk and clear screen for tin team security management systems
Lead Team Security ManagementRBI requires clear desk and clear screen for lead team security management systems
Zinc Team Security ManagementRBI requires clear desk and clear screen for zinc team security management systems
Nickel Team Security ManagementRBI requires clear desk and clear screen for nickel team security management systems
Titanium Team Security ManagementRBI requires clear desk and clear screen for titanium team security management systems
Tungsten Team Security ManagementRBI requires clear desk and clear screen for tungsten team security management systems
Platinum Team Security ManagementRBI requires clear desk and clear screen for platinum team security management systems
Silver Team Security ManagementRBI requires clear desk and clear screen for silver team security management systems
Gold Team Security ManagementRBI requires clear desk and clear screen for gold team security management systems
Mercury Team Security ManagementRBI requires clear desk and clear screen for mercury team security management systems
Sulfur Team Security ManagementRBI requires clear desk and clear screen for sulfur team security management systems
Carbon Team Security ManagementRBI requires clear desk and clear screen for carbon team security management systems
Nitrogen Team Security ManagementRBI requires clear desk and clear screen for nitrogen team security management systems
Oxygen Team Security ManagementRBI requires clear desk and clear screen for oxygen team security management systems
Hydrogen Team Security ManagementRBI requires clear desk and clear screen for hydrogen team security management systems
Helium Team Security ManagementRBI requires clear desk and clear screen for helium team security management systems
Neon Team Security ManagementRBI requires clear desk and clear screen for neon team security management systems
Argon Team Security ManagementRBI requires clear desk and clear screen for argon team security management systems
Krypton Team Security ManagementRBI requires clear desk and clear screen for krypton team security management systems
Xenon Team Security ManagementRBI requires clear desk and clear screen for xenon team security management systems
Radon Team Security ManagementRBI requires clear desk and clear screen for radon team security management systems
Fluorine Team Security ManagementRBI requires clear desk and clear screen for fluorine team security management systems
Chlorine Team Security ManagementRBI requires clear desk and clear screen for chlorine team security management systems
Bromine Team Security ManagementRBI requires clear desk and clear screen for bromine team security management systems
Iodine Team Security ManagementRBI requires clear desk and clear screen for iodine team security management systems
Astatine Team Security ManagementRBI requires clear desk and clear screen for astatine team security management systems
Tennessine Team Security ManagementRBI requires clear desk and clear screen for tennessine team security management systems
Lithium Team Security ManagementRBI requires clear desk and clear screen for lithium team security management systems
Sodium Team Security ManagementRBI requires clear desk and clear screen for sodium team security management systems
Potassium Team Security ManagementRBI requires clear desk and clear screen for potassium team security management systems
Rubidium Team Security ManagementRBI requires clear desk and clear screen for rubidium team security management systems
Cesium Team Security ManagementRBI requires clear desk and clear screen for cesium team security management systems
Francium Team Security ManagementRBI requires clear desk and clear screen for francium team security management systems
Beryllium Team Security ManagementRBI requires clear desk and clear screen for beryllium team security management systems
Magnesium Team Security ManagementRBI requires clear desk and clear screen for magnesium team security management systems
Calcium Team Security ManagementRBI requires clear desk and clear screen for calcium team security management systems
Strontium Team Security ManagementRBI requires clear desk and clear screen for strontium team security management systems
Barium Team Security ManagementRBI requires clear desk and clear screen for barium team security management systems
Radium Team Security ManagementRBI requires clear desk and clear screen for radium team security management systems
Scandium Team Security ManagementRBI requires clear desk and clear screen for scandium team security management systems
Yttrium Team Security ManagementRBI requires clear desk and clear screen for yttrium team security management systems
Lanthanum Team Security ManagementRBI requires clear desk and clear screen for lanthanum team security management systems
Actinium Team Security ManagementRBI requires clear desk and clear screen for actinium team security management systems
Titanium Team Security ManagementRBI requires clear desk and clear screen for titanium team security management systems
Zirconium Team Security ManagementRBI requires clear desk and clear screen for zirconium team security management systems
Hafnium Team Security ManagementRBI requires clear desk and clear screen for hafnium team security management systems
Rutherfordium Team Security ManagementRBI requires clear desk and clear screen for rutherfordium team security management systems
Vanadium Team Security ManagementRBI requires clear desk and clear screen for vanadium team security management systems
Niobium Team Security ManagementRBI requires clear desk and clear screen for niobium team security management systems
Tantalum Team Security ManagementRBI requires clear desk and clear screen for tantalum team security management systems
Dubnium Team Security ManagementRBI requires clear desk and clear screen for dubnium team security management systems
Chromium Team Security ManagementRBI requires clear desk and clear screen for chromium team security management systems
Molybdenum Team Security ManagementRBI requires clear desk and clear screen for molybdenum team security management systems
Tungsten Team Security ManagementRBI requires clear desk and clear screen for tungsten team security management systems
Seaborgium Team Security ManagementRBI requires clear desk and clear screen for seaborgium team security management systems
Manganese Team Security ManagementRBI requires clear desk and clear screen for manganese team security management systems
Technetium Team Security ManagementRBI requires clear desk and clear screen for technetium team security management systems
Rhenium Team Security ManagementRBI requires clear desk and clear screen for rhenium team security management systems
Bohrium Team Security ManagementRBI requires clear desk and clear screen for bohrium team security management systems
Iron Team Security ManagementRBI requires clear desk and clear screen for iron team security management systems
Ruthenium Team Security ManagementRBI requires clear desk and clear screen for ruthenium team security management systems
Osmium Team Security ManagementRBI requires clear desk and clear screen for osmium team security management systems
Hassium Team Security ManagementRBI requires clear desk and clear screen for hassium team security management systems
Cobalt Team Security ManagementRBI requires clear desk and clear screen for cobalt team security management systems
Rhodium Team Security ManagementRBI requires clear desk and clear screen for rhodium team security management systems
Iridium Team Security ManagementRBI requires clear desk and clear screen for iridium team security management systems
Meitnerium Team Security ManagementRBI requires clear desk and clear screen for meitnerium team security management systems
Nickel Team Security ManagementRBI requires clear desk and clear screen for nickel team security management systems
Palladium Team Security ManagementRBI requires clear desk and clear screen for palladium team security management systems
Platinum Team Security ManagementRBI requires clear desk and clear screen for platinum team security management systems
Darmstadtium Team Security ManagementRBI requires clear desk and clear screen for darmstadtium team security management systems
Copper Team Security ManagementRBI requires clear desk and clear screen for copper team security management systems
Silver Team Security ManagementRBI requires clear desk and clear screen for silver team security management systems
Gold Team Security ManagementRBI requires clear desk and clear screen for gold team security management systems
Roentgenium Team Security ManagementRBI requires clear desk and clear screen for roentgenium team security management systems
Zinc Team Security ManagementRBI requires clear desk and clear screen for zinc team security management systems
Cadmium Team Security ManagementRBI requires clear desk and clear screen for cadmium team security management systems
Mercury Team Security ManagementRBI requires clear desk and clear screen for mercury team security management systems
Copernicium Team Security ManagementRBI requires clear desk and clear screen for copernicium team security management systems
Boron Team Security ManagementRBI requires clear desk and clear screen for boron team security management systems
Aluminum Team Security ManagementRBI requires clear desk and clear screen for aluminum team security management systems
Gallium Team Security ManagementRBI requires clear desk and clear screen for gallium team security management systems
Indium Team Security ManagementRBI requires clear desk and clear screen for indium team security management systems
Thallium Team Security ManagementRBI requires clear desk and clear screen for thallium team security management systems
Nihonium Team Security ManagementRBI requires clear desk and clear screen for nihonium team security management systems
Carbon Team Security ManagementRBI requires clear desk and clear screen for carbon team security management systems
Silicon Team Security ManagementRBI requires clear desk and clear screen for silicon team security management systems
Germanium Team Security ManagementRBI requires clear desk and clear screen for germanium team security management systems
Tin Team Security ManagementRBI requires clear desk and clear screen for tin team security management systems
Lead Team Security ManagementRBI requires clear desk and clear screen for lead team security management systems
Flerovium Team Security ManagementRBI requires clear desk and clear screen for flerovium team security management systems
Nitrogen Team Security ManagementRBI requires clear desk and clear screen for nitrogen team security management systems
Phosphorus Team Security ManagementRBI requires clear desk and clear screen for phosphorus team security management systems
Arsenic Team Security ManagementRBI requires clear desk and clear screen for arsenic team security management systems
Antimony Team Security ManagementRBI requires clear desk and clear screen for antimony team security management systems
Bismuth Team Security ManagementRBI requires clear desk and clear screen for bismuth team security management systems
Moscovium Team Security ManagementRBI requires clear desk and clear screen for moscovium team security management systems
Oxygen Team Security ManagementRBI requires clear desk and clear screen for oxygen team security management systems
Sulfur Team Security ManagementRBI requires clear desk and clear screen for sulfur team security management systems
Selenium Team Security ManagementRBI requires clear desk and clear screen for selenium team security management systems
Tellurium Team Security ManagementRBI requires clear desk and clear screen for tellurium team security management systems
Polonium Team Security ManagementRBI requires clear desk and clear screen for polonium team security management systems
Livermorium Team Security ManagementRBI requires clear desk and clear screen for livermorium team security management systems
Fluorine Team Security ManagementRBI requires clear desk and clear screen for fluorine team security management systems
Chlorine Team Security ManagementRBI requires clear desk and clear screen for chlorine team security management systems
Bromine Team Security ManagementRBI requires clear desk and clear screen for bromine team security management systems
Iodine Team Security ManagementRBI requires clear desk and clear screen for iodine team security management systems
Astatine Team Security ManagementRBI requires clear desk and clear screen for astatine team security management systems
Tennessine Team Security ManagementRBI requires clear desk and clear screen for tennessine team security management systems
Hydrogen Team Security ManagementRBI requires clear desk and clear screen for hydrogen team security management systems
Helium Team Security ManagementRBI requires clear desk and clear screen for helium team security management systems
Neon Team Security ManagementRBI requires clear desk and clear screen for neon team security management systems
Argon Team Security ManagementRBI requires clear desk and clear screen for argon team security management systems
Krypton Team Security ManagementRBI requires clear desk and clear screen for krypton team security management systems
Xenon Team Security ManagementRBI requires clear desk and clear screen for xenon team security management systems
Radon Team Security ManagementRBI requires clear desk and clear screen for radon team security management systems
Oganesson Team Security ManagementRBI requires clear desk and clear screen for oganesson team security management systems

SEBI Cybersecurity Guidelines Mapping

SEBI RequirementMapping to A.7.7
Information ClassificationSEBI requires clear desk and clear screen for market-sensitive data
Access ManagementSEBI requires clear desk and clear screen for access management systems
Incident ManagementSEBI requires clear desk and clear screen for incident management systems
ComplianceSEBI requires clear desk and clear screen for compliance systems
Third-Party RiskSEBI requires clear desk and clear screen for third-party systems
Data ProtectionSEBI requires clear desk and clear screen for data protection systems
Business ContinuitySEBI requires clear desk and clear screen for business continuity systems
AuditSEBI requires clear desk and clear screen for audit systems
ReportingSEBI requires clear desk and clear screen for reporting systems
Market InfrastructureSEBI requires clear desk and clear screen for market infrastructure systems

DPDP Act 2023 Mapping

DPDP Act ProvisionMapping
Section 5, NoticeInform data principals about processing covered by this control
Section 6, ConsentObtain and manage consent for personal data processing
Section 8(1), Data Fiduciary responsibilityEnsure accountability for compliance with this control
Section 8(4), Technical and organisational measuresImplement appropriate measures to give effect to this control
Section 8(5), Reasonable security safeguardsProtect personal data through the safeguards in this control
Section 8(6), Personal data breach intimationDetect and notify relevant breaches to the Board and affected principals
Section 8(7), ErasureErase personal data when the purpose is no longer served
Section 8(10), Grievance redressal mechanismEstablish an effective grievance redressal mechanism
Section 9, Children and persons with disabilityApply enhanced safeguards when processing children's personal data
Section 10, Significant Data FiduciaryComply with additional SDF obligations (DPO, auditor, DPIA)
Section 11, Right to access informationEnable data principals to obtain information about their personal data
Section 12, Right to correction and erasureEnable correction, completion, updating and erasure requests
Section 13, Right of grievance redressalProvide readily available grievance redressal
Section 14, Right to nominationSupport nomination of a representative to exercise rights
Section 16, Cross-border transfersApply safeguards when transferring personal data outside India
Section 27, Powers and functions of BoardCooperate with the Data Protection Board of India
Section 33, PenaltiesNon-compliance may attract monetary penalties under the Schedule

Regulatory and Compliance Context

Indian Regulatory Requirements for Clear Desk and Clear Screen

Digital Personal Data Protection Act, 2023:

  • The DPDP Act requires "reasonable security safeguards" for personal data, which includes physical protection measures like clear desk and clear screen policies
  • Significant Data Fiduciaries must implement complete data protection measures, including physical security
  • Personal data processed in offices must be protected from unauthorized physical access
  • The Data Protection Board may review physical security practices during investigations

Information Technology Act, 2000:

  • Section 43A (prior to DPDP Act) required protection of sensitive personal data from unauthorized access, including physical access
  • Section 72 requires protection of confidentiality and privacy
  • The Official Secrets Act requires protection of classified information from physical exposure

RBI Cybersecurity Framework for Banks:

  • Banks must protect customer data from physical exposure in branch and back-office environments
  • Branch staff must follow clear desk practices to prevent customer data from being visible to other customers or visitors
  • Back-office staff must follow clear desk and clear screen policies for all customer data processing
  • RBI examiners will review physical security practices, including clear desk and clear screen compliance

SEBI Cybersecurity Guidelines:

  • Market infrastructure institutions must protect sensitive market data from physical exposure
  • Trading floors and dealing rooms must implement clear desk and clear screen policies
  • SEBI cybersecurity audits will review physical security practices

IRDAI Cybersecurity Guidelines:

  • Insurance companies must protect customer and health data from physical exposure
  • Claims processing and underwriting areas must implement clear desk and clear screen policies
  • IRDAI cybersecurity audits will review physical security practices

NABH Accreditation Standards for Hospitals:

  • Hospitals must protect patient information (PHI) from physical exposure
  • Clinical workstations, nurse stations, and patient areas must implement clear screen policies
  • Medical records and patient charts must be secured when not in use
  • NABH assessors will review physical security practices, including clear desk and clear screen

Defense and Government (Official Secrets Act):

  • Classified information must be protected from physical exposure at all times
  • Desks and screens in secure areas must be cleared when unattended
  • Unauthorized exposure of classified information is a criminal offense

Sector-Specific Clear Desk and Clear Screen Requirements

SectorRegulatory BodyKey Clear Desk/Clear Screen Requirements
BankingRBIClear desk in branches and back offices; clear screen for all customer data workstations; secure storage for customer documents; visitor controls in back offices; audit readiness
SecuritiesSEBIClear desk in trading floors and dealing rooms; clear screen for all trading workstations; secure storage for market data; visitor controls; audit readiness
InsuranceIRDAIClear desk in claims and underwriting; clear screen for all customer data workstations; secure storage for health and policy data; audit readiness
TelecomDoT/TRAIClear desk in customer service centers; clear screen for all customer data workstations; secure storage for customer records; audit readiness
HealthcareCDSCO/NABHClear desk in clinical and administrative areas; clear screen for all PHI workstations; secure storage for medical records; HIPAA compliance for US data; audit readiness
GovernmentNCIIPC/CERT-InClear desk in all government offices; clear screen for all workstations; secure storage for classified and sensitive data; Official Secrets Act compliance
DefenseMHA/DefenceClear desk in all defense facilities; clear screen for all workstations; secure storage for classified information; criminal penalties for exposure
IT/ITeSMeitYClear desk in all offices; clear screen for all workstations; secure storage for customer data; export control compliance; client audit readiness
E-commerceMeitY/Consumer AffairsClear desk in all offices; clear screen for all payment and customer data workstations; PCI DSS compliance; secure storage for customer data
EducationUGC/AICTEClear desk in administrative offices; clear screen for all student data workstations; secure storage for student records; audit readiness
Real EstateRERAClear desk in all offices; clear screen for all customer data workstations; secure storage for customer and transaction data
ManufacturingIndustry BodiesClear desk in all offices; clear screen for all IP and design workstations; secure storage for trade secrets and design data; export control compliance

RACI Matrix

Clear Desk and Clear Screen Activities RACI

ActivityBoardCISOFacilities ManagerSecurity ManagerIT ManagerHR ManagerAll EmployeesManagersCleaning Staff
Strategy and Policy
Define clear desk/screen policyARCCCCIII
Approve clear desk/screen policyARCCCCIII
Design enforcement proceduresCACRCCIII
Implementation
Deploy secure storageICACIIIII
Deploy automatic screen lockIAICRIIII
Install signage and remindersICACIIIII
Deploy secure print releaseICCCRIIII
Develop trainingIACRCCIII
Deliver trainingIACRCCIII
Operations
Clear own desk and screenIIIIIIRII
Perform end-of-day procedureIIIIIIRII
Conduct spot checksICARIIIRI
Conduct formal auditsIACRIIIII
Monitor complianceIACRIIIII
Address violationsIACRIRIRI
Manage cleaning staffIIACIIIIR
Audit and Compliance
Prepare audit evidenceIACRCIIII
Respond to findingsARCCCIIII
Report to managementARCCIIIII

R = Responsible, A = Accountable, C = Consulted, I = Informed


Documentation and Record Keeping

Required Documentation

DocumentPurposeRetention PeriodOwner
Clear Desk and Clear Screen PolicyDefines the policy and requirements7 yearsCISO
End-of-Day ProcedureStep-by-step procedure for employees3 yearsSecurity Manager
Training MaterialsTraining content for employees3 yearsSecurity Manager
Training Completion RecordsRecords of who completed training3 yearsHR
Spot Check RecordsRecords of informal spot checks1 yearSecurity Manager
Formal Audit RecordsRecords of formal compliance audits3 yearsSecurity Manager
Compliance Metrics ReportsMonthly/quarterly compliance reports3 yearsSecurity Manager
Violation RecordsRecords of policy violations and remediation7 yearsSecurity Manager
Disciplinary Action RecordsRecords of disciplinary actions for violations7 yearsHR
Exception RecordsApproved exceptions to the policy3 yearsCISO
Signage and Reminder InventoryInventory of signage and reminders deployed1 yearFacilities Manager
Secure Storage InventoryInventory of lockable storage (drawers, cabinets, lockers)1 yearFacilities Manager
Screen Lock ConfigurationTechnical configuration for screen lock enforcement3 yearsIT Manager
Secure Print Release ConfigurationTechnical configuration for secure print3 yearsIT Manager
Visitor and Contractor AgreementsAgreements acknowledging the policyDuration + 3 yearsSecurity Manager
Cleaning Staff Training RecordsTraining records for cleaning staff3 yearsFacilities Manager
Policy Review RecordsRecords of annual policy reviews3 yearsCISO
Incident Correlation RecordsRecords of incidents related to clear desk/screen violations7 yearsSecurity Manager
Audit ReportsInternal and external audit reports7 yearsCompliance

Record Keeping Best Practices

  • Centralized Repository: Maintain clear desk/screen records in a centralized system (shared drive, document management system, or security management system)
  • Access Control: Restrict access to compliance records based on role and need-to-know
  • Version Control: Track version history for the policy, procedures, and training materials
  • Audit Trail: Maintain complete audit trails for compliance monitoring, violations, and remediation
  • Backup: Clear desk/screen records are important for compliance and must be backed up
  • Privacy Compliance: Handle personal data in compliance records per DPDP Act
  • Legal Privilege: Protect compliance records related to litigation or investigation
  • Cross-Reference: Link compliance records to incident records, training records, and audit reports
  • Retention Compliance: Align retention with legal and regulatory requirements
  • Secure Destruction: Securely destroy records when retention periods expire
  • Real-Time Access: Enable real-time access to compliance metrics for management reporting
  • Reporting: Enable automated reporting on compliance rates and trends
  • Integration: Integrate compliance records with security awareness, incident management, and HR systems
  • Searchability: Ensure compliance records are searchable by employee, department, date, and violation type
  • Dashboards: Provide real-time dashboards for compliance status and trends

Continuous Improvement

Figure · Tiers

Maturity levels for clear desk and clear screen

  1. OptimizingNear-perfect compliance (≥99%)
  2. ManagedHigh compliance rates (≥95%)
  3. DefinedComplete policy with clear requirements
  4. DevelopingBasic policy exists but is not enforced
  5. InitialNo clear desk/screen policy
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Maturity Model for A.7.7

LevelNameCharacteristicsEvidence
1InitialNo clear desk/screen policy; no enforcement; no training; desks and screens routinely left unsecured; high visual hacking riskNo documentation, no controls, no enforcement, frequent violations
2DevelopingBasic policy exists but is not enforced; some training provided; some employees comply; spot checks are occasional; compliance is inconsistentBasic policy, some training, some compliance, some checks
3DefinedComplete policy with clear requirements; automatic screen lock deployed; secure storage available; training for all employees; regular spot checks and formal audits; violation handling; quarterly reviewComplete policy, automation, storage, training, monitoring, enforcement, review
4ManagedHigh compliance rates (≥95%); automated monitoring of screen lock compliance; secure print release deployed; visitor management integrated; cleaning staff trained; metrics-driven; positive reinforcement culture; integration with security awareness programHigh compliance, automation, integration, metrics, culture, positive reinforcement
5OptimizingNear-perfect compliance (≥99%); self-policing culture where employees correct each other; visitors and contractors automatically comply; remote work fully covered; policy is a competitive advantage; industry-leading practices; continuous optimizationSelf-policing, near-perfect compliance, competitive advantage, industry-leading

Improvement Cycle

Plan:

  • Annual policy and procedure review
  • Benchmarking against industry standards and peer organizations
  • Regulatory change assessment and alignment (DPDP Act, RBI, SEBI, NABH)
  • Technology evaluation for automation and enhancement (IoT, smart storage, biometric locks)
  • Maturity assessment and target setting
  • Incident analysis for lessons learned
  • Workspace risk assessment updates (new layouts, new areas, remote work changes)

Do:

  • Implement new automation tools (screen lock enforcement, secure print, smart storage)
  • Expand training to new employees and refresher for existing employees
  • Enhance signage and reminders with new designs and placements
  • Deploy new secure storage solutions (personal lockers, smart cabinets)
  • Extend policy to new areas (remote work, co-working spaces, new offices)
  • Enhance visitor and contractor controls
  • Improve cleaning staff training and supervision
  • Conduct security awareness campaigns focused on clear desk/screen
  • Implement positive reinforcement programs (recognition, rewards, contests)

Check:

  • Monthly compliance metrics review (clear desk rate, clear screen rate, violation trends)
  • Quarterly formal audit results review
  • Annual complete policy and procedure review
  • Compliance audit preparation and results
  • Employee feedback and comprehension assessment
  • overhead optimization and ROI measurement
  • Incident correlation analysis (violations vs. incidents)
  • Remote work compliance assessment
  • Visitor and contractor compliance assessment
  • Culture assessment (self-policing, peer awareness, positive reinforcement)

Act:

  • Update policy based on findings, incidents, and emerging risks
  • Refine procedures based on employee feedback and incident lessons
  • Invest in tools that improve automation, accuracy, and monitoring
  • Expand training for high-risk roles, new hires, and remote workers
  • Report improvements to leadership and board
  • Share best practices and lessons learned
  • Benchmark against industry standards and peer organizations
  • Engage with regulatory bodies on compliance
  • Participate in industry forums on physical security best practices
  • Publish illustrative scenarios and research on clear desk/screen effectiveness

Toolkit Download

The following toolkit assets are available for this control:

AssetDescriptionFormat
01-clear-desk-clear-screen-policy-template.mdComplete policy template with enforcement proceduresMarkdown
02-end-of-day-checklist-template.docxEnd-of-day security checklist for employeesWord
03-spot-check-checklist-template.docxSpot check and audit checklist for security/facilitiesWord
04-training-presentation-clear-desk-screen.pptxTraining deck with scenarios and knowledge testPowerPoint
05-screen-lock-configuration-guide.mdGPO/MDM screen lock configuration guideMarkdown
06-signage-and-reminder-templates.zipDesk plates, posters, stickers, and keyboard sticker designsZIP (PNG/PDF)
07-secure-print-release-guide.mdSecure print release deployment guideMarkdown
08-visitor-contractor-agreement-template.docxVisitor and contractor acknowledgment templateWord
09-meeting-room-security-guide.mdMeeting room and whiteboard security guideMarkdown
10-remote-work-clear-desk-guide.mdRemote work and home office adaptation guideMarkdown
11-compliance-metrics-dashboard.xlsxDashboard for tracking clear desk/screen KPIsExcel
12-violation-handling-flowchart.docxViolation handling flowchart and disciplinary matrixWord
13-cleaning-staff-training-guide.mdCleaning staff training and supervision guideMarkdown
14-audit-evidence-checklist.mdEvidence checklist for A.7.7 audit preparationMarkdown
15-exception-request-form.docxException request and approval formWord
16-incident-response-template.docxVisual hacking/physical exposure incident response templateWord
17-maturity-assessment-questionnaire.mdSelf-assessment for clear desk/screen program maturityMarkdown
README.mdIndex and usage guide for all toolkit assetsMarkdown

Frequently Asked Questions

Q1: Is clear desk and clear screen mandatory for ISO 27001 certification?

A: Yes. A.7.7 explicitly requires "a clear desk policy for papers and removable storage media and a clear screen policy for information processing facilities" to be "adopted and appropriately enforced." This is a core control that auditors will always review during physical security assessments. A single unattended desk with a sensitive document or an unlocked screen can be a finding.

Q2: How short should the automatic screen lock timeout be?

A: The timeout depends on the risk level of the environment:

  • High-risk environments (BPO, trading floors, healthcare, areas with high visitor traffic): 2–3 minutes
  • Standard office environments: 5 minutes
  • Low-risk environments (private offices with no visitor access): 10 minutes
  • Public/shared terminals: 1 minute The timeout should be short enough to prevent unauthorized access during brief absences (bathroom breaks, coffee runs) but not so short that it frustrates users and causes them to find workarounds. For most organizations, 5 minutes is the standard recommendation. For high-risk environments, 2–3 minutes is appropriate. Test the timeout with a pilot group before full deployment.

Q3: Do we need to provide lockable storage for every employee?

A: Yes, every employee who handles sensitive information must have access to lockable storage. At minimum, every desk should have at least one lockable drawer. In open-plan or hot-desking environments, personal lockers should be provided. The storage does not need to be premium-tier, a simple lockable desk drawer or a small filing cabinet is sufficient. The key is that employees have somewhere to put sensitive documents and media when they leave their desk. Without lockable storage, the policy is unenforceable.

Q4: How do we handle employees who say the policy is too inconvenient?

A: Inconvenience is a common complaint, but it can be addressed by: (1) making secure storage easily accessible (lockable drawer at the desk, not a cabinet across the room), (2) making screen lock automatic (not manual), (3) explaining the "why", real-world examples of breaches caused by visual hacking and document theft, (4) sharing compliance metrics that show the policy works, (5) making the end-of-day procedure a quick 2-minute routine, not a 30-minute chore, (6) providing positive reinforcement for compliance, not just punishment for violations. The key is to make compliance easier than non-compliance. If locking a drawer takes 5 seconds and the alternative is a disciplinary warning, employees will lock the drawer.

Q5: Should we enforce clear desk at the end of the day, or also during the day when employees leave for lunch or breaks?

A: Both. The policy should require clearing the desk whenever the employee is not present, even for short periods. This includes lunch breaks, coffee breaks, bathroom breaks, meetings, and any other absence from the desk. The rationale is that an attacker or visitor only needs a few seconds to photograph a document or copy a USB drive. However, the policy should be practical: documents actively being worked on can remain on the desk while the employee is present, but must be secured when the employee leaves. The end-of-day clearance is the most critical (all items secured overnight), but daytime clearance is also important.

Q6: How do we handle open-plan offices where desks are visible to everyone?

A: Open-plan offices are the highest-risk environment for clear desk violations because every desk is visible to everyone. In open-plan offices: (1) enforce the strictest clear desk policy (no sensitive documents visible when unattended), (2) provide personal lockers or lockable drawers for every employee, (3) use desk dividers or privacy screens to reduce visual exposure, (4) position screens to face away from main walkways (not toward reception or visitor areas), (5) use privacy filters on screens to reduce angle visibility, (6) conduct frequent spot checks, (7) train employees on the risks of open-plan layouts. Open-plan offices are popular for overhead and collaboration, but they require the most rigorous clear desk enforcement.

Q7: What about hot-desking and shared workstations?

A: Hot-desking and shared workstations require adapted controls: (1) employees must clear the desk completely before leaving (no personal or sensitive items left behind), (2) screens must log out after each session (not just lock), (3) personal lockers must be provided for storing items between shifts, (4) shared workstations should have "session end" buttons that log out and clear temporary files, (5) USB ports may be disabled on shared workstations to prevent media storage, (6) each user should use their own credentials and not share accounts. Hot-desking environments are actually easier for clear desk enforcement because employees are already in the habit of taking their belongings with them when they leave.

Q8: How do we handle remote workers and home offices?

A: Remote workers must follow an adapted clear desk/clear screen policy: (1) lock screens when leaving the workstation, even at home, (2) secure sensitive documents in a locked drawer or cabinet when not in use, (3) ensure screens and documents are not visible to family members, visitors, or delivery personnel, (4) collect and secure all materials when working in shared spaces (co-working, coffee shops), (5) use privacy filters on screens in shared spaces, (6) do not leave work devices unattended in public spaces. Provide remote workers with guidance on home office setup, including secure storage recommendations. Include remote workers in training and compliance monitoring (via self-assessment or periodic check-ins).

Q9: How do we handle meeting rooms with whiteboards and flip charts?

A: Meeting rooms are a common source of data exposure. Controls: (1) all whiteboards must be erased after meetings; provide erasers and signs, (2) flip chart pages with sensitive content must be removed and stored securely or shredded, (3) digital whiteboards must be configured to clear content after meetings, (4) meeting rooms must be checked after each meeting for left-behind documents, laptops, or devices, (5) meeting rooms should have "erase after use" signs, (6) for highly sensitive meetings, consider non-permanent markers or digital whiteboards that don't retain physical traces. Assign a "meeting owner" responsibility to ensure the room is cleared.

Q10: How do we measure the effectiveness of clear desk and clear screen?

A: Key effectiveness indicators: (1) Clear desk compliance rate, percentage of desks compliant during spot checks (target: ≥95%), (2) Clear screen compliance rate, percentage of screens locked during spot checks (target: ≥99%), (3) End-of-day compliance rate, percentage of employees performing end-of-day procedure (target: ≥95%), (4) Violation rate, number of violations per month (target: decreasing trend), (5) Repeat violation rate, percentage of violations that are repeat offenses (target: ≤10%), (6) Training completion rate, percentage of employees completing training (target: ≥95%), (7) Training test score, average score on knowledge test (target: ≥90%), (8) Visual hacking incidents, number of visual hacking incidents detected (target: 0), (9) Document theft incidents, number of document theft incidents (target: 0), (10) Audit findings, number of clear desk/screen-related audit findings (target: 0). Measure baseline before implementation and track trends over time. Report improvements to leadership quarterly.

Q11: What should we do when visitors or auditors request to see documents or screens?

A: Visitors and auditors should never be allowed to view sensitive documents or screens without authorization. If an auditor needs to review documents, they must be provided in a controlled manner (e.g., in a meeting room, with an authorized employee present, with only the specific documents needed). If an auditor needs to see a system, they must be shown a demo or test environment, not the production system with live data. Visitors should be restricted to designated visitor areas. If a visitor needs to see a work area, they must be escorted, and the area should be prepared in advance (desks cleared, screens locked, sensitive documents removed). Never allow an unescorted visitor to walk through a work area.

Q12: How do we handle clear desk during emergencies (fire alarm, evacuation)?

A: During emergencies, personal safety takes priority over clear desk compliance. Employees should not delay evacuation to secure documents. However, the organization should consider: (1) the fire alarm or evacuation drill may be used as a social engineering tactic to clear the office for theft, so security personnel should monitor the area during evacuations, (2) after the emergency, employees should check their desks and report any missing items, (3) for planned drills, employees can practice "quick clear" procedures (taking critical items with them), (4) emergency procedures should be documented and communicated. The key is to balance safety with security, never require employees to risk safety for document security, but have post-incident procedures to address any exposure during the emergency.

Q13: Should we use screen privacy filters?

A: Screen privacy filters are recommended for high-risk environments (open-plan offices, customer-facing desks, areas with high visitor traffic). Privacy filters limit the viewing angle of the screen, so only the person directly in front of the screen can see the content. They are particularly useful for: (1) open-plan offices where screens are visible to neighbors, (2) reception and customer service desks where screens may be visible to customers, (3) areas where shoulder surfing is a risk, (4) employees who work with highly sensitive data (finance, HR, legal). Privacy filters are not a substitute for screen locks, they should be used in combination with screen locks. They are relatively inexpensive (–per screen) and can be installed by the user.

Q14: How do we handle cleaning staff who need to clean desks?

A: Cleaning staff are a common challenge for clear desk policies because they need to access desks to clean them. Solutions: (1) cleaning staff should be screened and trained on the clear desk policy, (2) cleaning staff should be supervised or work in teams, (3) cleaning should be scheduled during work hours when employees are present (if feasible), or after hours with security supervision, (4) cleaning staff should not access locked drawers or cabinets, (5) cleaning staff should report any sensitive documents found on desks to security or facilities, (6) cleaning staff should be required to sign confidentiality agreements. In high-security environments, cleaning staff may be escorted or limited to specific areas. The key is to balance the need for cleaning with the need for security.

Q15: How do we maintain compliance over the long term?

A: Long-term compliance requires: (1) Automation, automatic screen lock removes the human factor for screens, (2) Integration, make clear desk/screen part of the organizational culture, not a separate security initiative, (3) Reinforcement, periodic reminders, training, and awareness campaigns keep the topic fresh, (4) Metrics, track and publish compliance rates to maintain accountability, (5) Leadership modeling, executives and managers must visibly comply with the policy to set the tone, (6) Positive culture, create a culture where employees remind each other and take pride in security, rather than viewing it as a burden, (7) New hire training, every new employee learns the policy from day one, (8) Continuous improvement, review and refine the policy based on incidents, feedback, and changes in the work environment. Compliance is not a one-time project, it is a continuous practice that requires ongoing attention.


The following toolkit assets are available for this control:

#Toolkit FileDescription
101-clear-desk-and-clear-screen-policy-template.mdPolicy Template
202-clear-desk-and-clear-screen-procedure.mdProcedure
303-clear-desk-and-clear-screen-checklist.mdChecklist
404-audit-evidence-checklist.mdAudit Evidence Checklist
505-implementation-roadmap.mdImplementation Roadmap
606-quick-reference-card.mdQuick Reference Card
707-training-materials.mdTraining Materials
808-incident-response-playbook.mdIncident Response Playbook
909-risk-assessment-template.mdRisk Assessment Template
1010-vendor-security-template.mdVendor Security Template
1111-metrics-and-kpi-dashboard.mdMetrics and KPI Dashboard
1212-gap-analysis-template.mdGap Analysis Template
1313-raci-matrix.mdRACI Matrix
1414-tool-comparison-matrix.mdTool Comparison Matrix
1515-communication-plan.mdCommunication Plan
1616-roles-and-responsibilities.mdRoles and Responsibilities
1717-regulatory-mapping.mdRegulatory Mapping

References and Further Reading

Standards and Frameworks

  • ISO/IEC 27001:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements
  • ISO/IEC 27002:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Controls
  • NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations
  • COBIT 2019, IT Governance and Management Framework
  • CIS Controls v8, Controls 1 (Inventory and Control of Enterprise Assets) and 4 (Secure Configuration)
  • PCI DSS v4.0, Physical Security Requirements for Cardholder Data Environment
  • HIPAA Security Rule, Physical Safeguards (Workstation Security, Device and Media Controls)
  • GDPR, Article 32 (Security of Processing, including physical security)
  • Digital Personal Data Protection Act, 2023
  • Information Technology Act, 2000 (as amended through 2008)
  • Official Secrets Act, 1923 (for government and defense classified information)
  • RBI Cybersecurity Framework for Banks (2016, updated)
  • SEBI Cybersecurity Guidelines for Market Infrastructure Institutions (2019)
  • IRDAI Cybersecurity Guidelines for Insurance Companies (2017)
  • NABH Accreditation Standards for Hospitals (relevant to patient information protection)
  • Indian Penal Code, 1860 (relevant sections on theft and breach of trust)
  • Companies Act, 2013 (relevant to data protection and board responsibility)

Industry and Research Sources

  • Ponemon Institute, Visual Hacking Study (2019, 2023)
  • SANS Institute, Physical Security and Visual Hacking Resources
  • ISACA, Physical Security Governance and Risk Management Guidance
  • Gartner Research, Physical Security and Workplace Security
  • Forrester Research, Security Awareness and Behavioral Change
  • IBM Research, Security Culture and Employee Behavior
  • Verizon Data Breach Investigations Report (physical security and insider threat statistics)
  • "Visual Hacking: The Simplest Form of Data Breach", Security Magazine
  • "The Psychology of Clear Desk Policies", Journal of Information Security and Privacy
  • "Physical Security in the Modern Workplace", ASIS International

Tool Documentation

  • Microsoft Group Policy Documentation, Screen Saver and Screen Lock Configuration
  • Microsoft Intune Documentation, Device Compliance and Screen Lock Policies
  • VMware Workspace ONE Documentation, Device Management and Security Policies
  • Jamf Pro Documentation, macOS Security and Screen Lock Configuration
  • MobileIron Documentation, Mobile Device Security and Screen Lock
  • Various printer manufacturer documentation for Secure Print Release (HP, Canon, Ricoh, Xerox)
  • Various CCTV and visitor management system documentation

Open Source Resources

  • Custom PowerShell scripts for Windows screen lock enforcement and monitoring
  • Custom Bash scripts for Linux screen lock configuration
  • Custom scripts for screen lock compliance auditing and reporting
  • Custom scripts for printer secure print release configuration
  • Open-source visitor management systems (e.g., SimpleVisitor, VisitorLog)
  • Open-source security awareness training platforms (e.g., SecurityEducation, PhishTank)
  • Custom scripts for compliance metric tracking and dashboard generation

Document Control

  • Version: 1.0
  • Author: Singahi, ISO 27001 Implementation Experts
  • Review Cycle: Quarterly + Annual
  • Next Review: September 2026 (quarterly) / June 2027 (annual)
  • Classification: TLP:CLEAR, Public Information

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.