Skip to content
arrow_back
search
Annex A 7.7 verified ISO/IEC 27001:2022

Clear desk and clear screen policies

Ensure desks and screens are clear of sensitive info to prevent unauthorized access.

record_voice_over

Plain language

This control is like making sure you don't leave important stuff lying around in plain sight, like your diary open on the kitchen table. It matters because if someone sees your private notes, they might misuse that information. Keeping desks and screens clear of sensitive info prevents unauthorised people from seeing or accessing it, protecting your important data and your organisation's reputation.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Physical controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

12 Apr 2026

Maturity levels

N/A

Official control statement

Clear desk rules for papers and removable storage media and clear screen rules for information processing facilities shall be defined and appropriately enforced.
verified ISO/IEC 27001:2022 Annex A 7.7
priority_high

Why it matters

Sensitive information left visible on desks or screens can be accessed by unauthorised people, causing data leakage, compliance breaches and reputational damage.

settings

Operational notes

Run periodic spot checks and reminders: lock screens when away, clear papers/removable media from desks, and store items in locked cabinets at day end.

Mapping detail

Mapping

Direction

Controls