Clear Desk and Clear Screen Policy
A Clear Desk and Clear Screen Policy is a set of workplace rules requiring staff to secure or remove sensitive information, whether on paper or on their computer screens, whenever a desk or device is left unattended. Its aim is to reduce the chance that unauthorized people can see, take, or damage confidential information. It typically applies to both physical documents and digital displays across an organization's workspaces.
The Clear Desk and Clear Screen Policy is an organizational and physical control addressing the protection of information in both paper and electronic form when a workspace, device, or facility is unattended. In practice it commonly requires that sensitive documents, removable storage media, and printed materials be cleared or secured when desks are left unoccupied, and that screens be locked or protected to prevent viewing of restricted information. Within the ISO/IEC 27001 framework it corresponds to a reference control in Annex A (identified as control 7.7 in the 2022 revision); as with all Annex A controls, its applicability is determined through the Statement of Applicability and informed by risk assessment rather than being universally mandatory. The specific measures, scope, and enforcement typically vary by organization and are shaped by the classification of information handled and the environments in which staff operate.
Why it matters
Information exposed on an unattended desk or an unlocked screen is one of the most avoidable sources of unauthorized access. A printed contract left in a shared area, a sticky note bearing a password, a USB drive on a desktop, or a logged-in workstation displaying customer records can all be viewed, copied, or removed by anyone passing by, whether a visitor, contractor, cleaning staff, or another employee outside the need-to-know boundary. A Clear Desk and Clear Screen Policy addresses this risk directly by requiring that sensitive information, in both paper and electronic form, be secured or removed whenever a workspace is left unoccupied. Its purpose, as reflected in common implementations, is to reduce the risk of unauthorized access to, loss of, and damage to information both during and outside normal working hours.
The control matters because it covers a gap that technical safeguards alone do not close. Encryption, network controls, and access management protect data in systems, but they do little for a document sitting face-up in an open-plan office or a screen left visible during a lunch break. This is especially relevant in shared, hybrid, and public-facing environments where people who are not authorized to see restricted information regularly move through the same physical space.
Within the ISO/IEC 27001 framework, this corresponds to an Annex A reference control (identified as control 7.7 in the 2022 revision). As with all Annex A controls, its applicability is not automatic; it is determined through the Statement of Applicability and informed by the organization's risk assessment. Organizations should therefore treat it as a risk-driven measure whose scope and rigor depend on the sensitivity of the information handled and the environments in which staff operate, rather than as a one-size-fits-all requirement.
Who it's relevant to
Inside Clear Desk and Clear Screen Policy
Common questions
Answers to the questions practitioners most commonly ask about Clear Desk and Clear Screen Policy.