Skip to main content
Category: Technical Security Controls

Clear Desk and Clear Screen Policy

Also known as: Clean Desk and Clear Screen Policy, Clear Desk Policy, Clear Screen Policy
Simply put

A Clear Desk and Clear Screen Policy is a set of workplace rules requiring staff to secure or remove sensitive information, whether on paper or on their computer screens, whenever a desk or device is left unattended. Its aim is to reduce the chance that unauthorized people can see, take, or damage confidential information. It typically applies to both physical documents and digital displays across an organization's workspaces.

Formal definition

The Clear Desk and Clear Screen Policy is an organizational and physical control addressing the protection of information in both paper and electronic form when a workspace, device, or facility is unattended. In practice it commonly requires that sensitive documents, removable storage media, and printed materials be cleared or secured when desks are left unoccupied, and that screens be locked or protected to prevent viewing of restricted information. Within the ISO/IEC 27001 framework it corresponds to a reference control in Annex A (identified as control 7.7 in the 2022 revision); as with all Annex A controls, its applicability is determined through the Statement of Applicability and informed by risk assessment rather than being universally mandatory. The specific measures, scope, and enforcement typically vary by organization and are shaped by the classification of information handled and the environments in which staff operate.

Why it matters

Information exposed on an unattended desk or an unlocked screen is one of the most avoidable sources of unauthorized access. A printed contract left in a shared area, a sticky note bearing a password, a USB drive on a desktop, or a logged-in workstation displaying customer records can all be viewed, copied, or removed by anyone passing by, whether a visitor, contractor, cleaning staff, or another employee outside the need-to-know boundary. A Clear Desk and Clear Screen Policy addresses this risk directly by requiring that sensitive information, in both paper and electronic form, be secured or removed whenever a workspace is left unoccupied. Its purpose, as reflected in common implementations, is to reduce the risk of unauthorized access to, loss of, and damage to information both during and outside normal working hours.

The control matters because it covers a gap that technical safeguards alone do not close. Encryption, network controls, and access management protect data in systems, but they do little for a document sitting face-up in an open-plan office or a screen left visible during a lunch break. This is especially relevant in shared, hybrid, and public-facing environments where people who are not authorized to see restricted information regularly move through the same physical space.

Within the ISO/IEC 27001 framework, this corresponds to an Annex A reference control (identified as control 7.7 in the 2022 revision). As with all Annex A controls, its applicability is not automatic; it is determined through the Statement of Applicability and informed by the organization's risk assessment. Organizations should therefore treat it as a risk-driven measure whose scope and rigor depend on the sensitivity of the information handled and the environments in which staff operate, rather than as a one-size-fits-all requirement.

Who it's relevant to

Compliance and GRC Managers
Those responsible for an ISO 27001 ISMS need to decide whether this Annex A control (7.7 in the 2022 revision) is applicable, document that decision in the Statement of Applicability, and tie it back to the risk assessment. They also define the policy's scope, classification triggers, and enforcement approach appropriate to their organization.
Security Engineers and IT Administrators
Technical staff often implement the clear screen aspects, such as automatic screen locking and protecting displays from unauthorized viewing when devices are left unattended. They help translate policy requirements into practical, consistently applied configurations across workstations.
Auditors and Certification Assessors
Assessors reviewing an ISMS may look for evidence that, where this control is deemed applicable, sensitive documents and media are secured when desks are unattended and screens are protected. Because applicability and specific measures vary by scope and risk, they evaluate the control against how the organization has defined it rather than against a universal checklist.
General Staff and People Managers
Because the policy governs everyday behavior, clearing desks of sensitive papers and media, and locking screens when stepping away, it is relevant to all employees who handle confidential information. Managers reinforce adherence, particularly in shared, hybrid, or public-facing workspaces where unauthorized viewing is more likely.

Inside Clear Desk and Clear Screen Policy

Clear Desk Requirement
A policy provision requiring that sensitive information in physical form, papers, printouts, removable media, and portable devices, be secured away or removed from unattended workspaces to reduce the risk of unauthorized access or disclosure.
Clear Screen Requirement
A policy provision requiring that display screens be locked, logged off, or otherwise protected when a workstation is left unattended, typically supported by automatic screen locks after a period of inactivity, so that information is not visible to unauthorized individuals.
Scope of Covered Assets
The definition of what the policy applies to, which may include desks, printers, fax machines, screens, whiteboards, removable media, and physical documents. The precise scope depends on the organization and the environment being protected.
Alignment with ISO 27001 Annex A
In ISO/IEC 27001, a clear desk and clear screen control appears among the Annex A reference controls, which are selected via the Statement of Applicability and informed by risk assessment. Whether it applies to a given ISMS depends on scope; specific control numbering depends on the edition (for example, the 2022 revision restructured Annex A into 93 controls across four themes).
Relationship to SOC 2 Trust Services Criteria
Under SOC 2, physical and logical access safeguards of this kind may support the Security category (the Common Criteria) that is required in every engagement, and potentially Confidentiality if that optional category is in scope. It is not a standalone SOC 2 requirement but may form part of the controls an organization presents for examination.
Enforcement and Awareness Mechanisms
The operational elements that make the policy effective, which typically include employee awareness communications, periodic reminders, and monitoring or spot checks. The chosen mechanisms vary depending on organizational scope and risk appetite.

Common questions

Answers to the questions practitioners most commonly ask about Clear Desk and Clear Screen Policy.

Is a Clear Desk and Clear Screen Policy a mandatory control that every organization must implement?
Not as an absolute rule. Under ISO/IEC 27001, Annex A functions as a set of reference controls that are selected via the Statement of Applicability and informed by risk assessment, so a clear desk and clear screen control is included or excluded based on your organization's scope and risk decisions rather than being universally required. For SOC 2, whether this type of physical and logical safeguard is addressed depends on the Trust Services Criteria in scope and the auditor's evaluation of your control environment. In most engagements it is a common and expected practice, but describing it as strictly mandatory overstates the requirement.
Does having a Clear Desk and Clear Screen Policy mean information is guaranteed to be protected from exposure?
No. A policy documents an intended behavior and set of expectations; it does not by itself guarantee freedom from information exposure. Its effectiveness depends on how consistently it is implemented and operated, which is why a SOC 2 Type II examination assesses operating effectiveness over a defined review period rather than treating the existence of a policy as sufficient. Even where controls are found suitably designed and operating effectively, the outcome attests only to the controls and period covered and does not guarantee that no exposure or breach will occur.
What practical measures are typically included when implementing a Clear Desk and Clear Screen Policy?
Implementations typically address both physical documents and on-screen information. Common measures include securing sensitive papers and removable media when workspaces are unattended, locking screens or invoking session locks after a period of inactivity, and positioning or shielding displays to reduce unauthorized viewing. The specific measures adopted depend on scope, the sensitivity of information handled, and the risk assessment that informs control selection, so the exact combination varies by organization.
How can an organization demonstrate that a Clear Desk and Clear Screen Policy is operating effectively for an audit?
Because a SOC 2 Type II examination assesses operating effectiveness over a defined review period, organizations generally maintain evidence that the policy is applied consistently rather than merely documented. Depending on scope and the auditor's approach, this can include records of periodic workspace or walkthrough checks, configuration evidence for automatic session or screen locking, and awareness or acknowledgment records. For ISO/IEC 27001, alignment with the Statement of Applicability and evidence gathered during internal and certification body assessments typically supports the demonstration. The precise evidence expected varies by auditor, certification body, and scope.
How should a Clear Desk and Clear Screen Policy account for remote and hybrid work arrangements?
Where remote or hybrid work is within scope, organizations typically extend the policy's expectations beyond the traditional office to home and other work locations, addressing how physical documents are secured and how screens are locked or shielded in less controlled environments. The appropriate approach depends on the organization's risk assessment and the scope of the environment being covered, so specifics vary between engagements.
How does a Clear Desk and Clear Screen Policy relate to other controls in a security program?
It generally operates alongside related controls rather than in isolation. In most programs it complements access management, session and endpoint configuration, physical security, and information classification and handling practices. Under ISO/IEC 27001 its selection is coordinated through the Statement of Applicability and the broader ISMS requirements in clauses 4 through 10, while under SOC 2 it may support the Security (Common Criteria) category and, depending on scope, any additional Trust Services Criteria selected. How it interacts with other controls depends on the overall control environment and scope.

Common misconceptions

A clear desk and clear screen control is a mandatory control that every organization must implement to pass SOC 2 or ISO 27001.
For ISO/IEC 27001, Annex A controls are reference controls selected through the Statement of Applicability and informed by risk assessment, so applicability depends on scope rather than being universally required. For SOC 2, the auditor evaluates the controls the organization has defined against the applicable Trust Services Criteria, so the specific approach is not fixed. In most engagements it is a common safeguard, but it is not automatically compulsory in either framework.
Implementing a clear desk and clear screen policy for ISO 27001 automatically satisfies the equivalent SOC 2 expectation and vice versa.
Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one framework does not automatically satisfy the other. The Trust Services Criteria are distinct from ISO 27001 Annex A controls, and each engagement evaluates the control against its own criteria and scope.
The policy only concerns physical paper on desks.
Depending on scope, the policy typically also addresses screens, removable media, portable devices, printers, and other means by which information could be exposed. The clear screen aspect specifically targets electronic displays left unattended, so limiting the policy to paper documents would leave gaps.

Best practices

Define the scope of the policy explicitly, identifying the workspaces, devices, media, and document types it covers, and align that scope with the organization's risk assessment and, where relevant, the ISO 27001 Statement of Applicability.
Configure automatic screen locks after a period of inactivity so that clear screen expectations do not rely solely on manual user action.
Reinforce the policy through recurring awareness communications and reminders, since consistent operation over time is what typically supports a SOC 2 Type II examination of operating effectiveness.
Provide secure storage such as lockable drawers or cabinets for sensitive documents and removable media so employees have a practical means to comply.
Consider periodic spot checks or walkthroughs to monitor adherence, adjusting the approach based on organizational scope and risk appetite rather than assuming a single method is required.
Document the control and retain evidence of its operation, recognizing that any resulting SOC 2 report attests only to the controls and period covered and an ISO 27001 certificate covers only the defined ISMS scope, so neither guarantees freedom from incidents.