Skip to content
compliancebase
ISO 27001A.7 — Clear desk and clear screen

A.7.7

Clear desk and clear screen

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Apply clear desk and clear screen rules to protect information on desks, screens, and other visible surfaces.

Points of focus

  • Screen lock policy
  • Rules for printed sensitive documents
  • Meeting room whiteboard hygiene
  • Remote/public space expectations

Implementation notes

Set OS lock ≤5–15 minutes via MDM. Ban printing production credentials. Train support staff on public-space screen caution. Include clear desk in office security awareness. Assign a named owner in the SoA, tie operating evidence to clear desk/screen policy, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Show MDM lock settings and policy text. Walk the office for obvious paper PII if physical scope exists.

Evidence auditors typically request:

  • Clear desk/screen policy
  • Endpoint screen-lock GPO/MDM setting
  • Spot-check or audit notes
  • Secure print / shred guidance

Common gaps

  • No automatic lock
  • Customer lists pinned to monitors
  • Whiteboards left with credentials after standup

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.7This control
SOC 2CC6.1Related SOC 2 themes (CC6.1) — map in your crosswalk; not identical requirements.
GDPRArticle 32Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Screen lock and public-space rules still apply; desk paper rules matter less.

Yes — and an authentication control failure.

Discourage production work in public; require privacy screens if unavoidable.

Even without owned data centers, clear desk and clear screen still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with clear desk/screen policy, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above