Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Clean desk policy rules for ISO 27001 Annex A 7.7 clear desk and clear screen

Clean Desk Policy: 9 Essential Rules for 2026

A clean desk policy is the least glamorous control in an information security management system and one of the most frequently failed. Not failed on paper — almost everyone has the document. Failed in the audit, when the auditor walks the floor at four o’clock and finds a printed payroll report on an empty desk.

This guide covers what ISO 27001 actually requires, the nine rules a workable policy contains, the half of the control most organisations forget, and how to evidence it when the auditor asks.

Clean desk or clear desk? The terminology matters

ISO 27001:2022 does not use the phrase “clean desk”. Annex A control 7.7 is titled Clear desk and clear screen, and it asks that clear desk rules for papers and removable storage media, and clear screen rules for information processing facilities, are defined and appropriately enforced.

The two terms describe the same thing, and either title on your document is fine. What is not fine is writing a clean desk policy that covers only the desk. The control is explicitly two-part, and the screen half is where the real exposure sits in a hybrid workplace — a locked drawer protects a printout, but nothing protects an unlocked laptop in a co-working space.

If you name the document “Clean Desk Policy” because that is what your staff will search for, add a line stating that it implements clear desk and clear screen requirements. Auditors map documents to controls, and making the mapping obvious saves a conversation.

Why the control still exists

It is tempting to treat this as a relic of the paper office. The threat model has changed rather than disappeared.

Visual exposure now happens on trains, in cafés, in shared houses and on video calls where a whiteboard is in shot. Printed material has become rarer and therefore more concentrated: when something is printed today it is usually because it mattered — a contract, a payroll run, a board pack. And the biggest single change is that “the office” is now dozens of unsupervised locations that your physical security controls do not reach.

A clean desk policy is also one of the few security controls that non-technical staff can see working. That makes it disproportionately useful for security culture, and disproportionately damaging when leadership visibly ignores it.

The nine rules a clean desk policy needs

Keep it short enough that people read it once and remember it. Nine rules is about the ceiling.

  1. Clear at the end of the day. Papers and removable media go into locked storage when the desk is unattended overnight.
  2. Clear for extended absence. Lunch, meetings, end of a hot-desk booking — anything classified above internal use does not stay out.
  3. Lock the screen every time you stand up. Manual lock, not just the timeout.
  4. Automatic lock as a backstop. A short inactivity timeout with authentication to unlock, because people forget.
  5. Collect print jobs immediately. Pull printing where you have it; a named collection rule where you do not.
  6. Whiteboards get wiped. Including after external visitors and before video calls that show the room.
  7. Removable media is locked away. USB drives, backup media and anything else portable and readable.
  8. Secure disposal. Confidential waste bins or cross-cut shredders, never the general recycling.
  9. The rules apply at home. Same expectations for home and remote workspaces, with lockable storage provided where the role needs it.

Two things make the difference between rules people follow and rules they resent. Give them somewhere to put things — a clear desk policy in an office with no lockable storage is an instruction to break the rules. And set the inactivity timeout at a length that reflects the actual risk of the space; five minutes in a public area is sensible, five minutes at a solo home desk mostly generates irritation and workarounds.

The clear screen half nobody writes

Most published policies devote nine paragraphs to paper and one line to screens. Reverse the emphasis and the document starts matching the risk.

Exposure Control Where it applies
Unattended unlocked session Manual lock plus inactivity timeout Everywhere
Shoulder surfing Privacy filter; screen positioning Public spaces, open plan
Screen sharing overspill Share a window, never the whole desktop Video calls
Notifications on lock screen Suppress previews for work accounts Laptops and phones
Background in shot Blur or virtual background; wipe whiteboards Home and meeting rooms
Shared or family devices Separate profiles; prohibit shared logins Home working

Notification previews are the one people miss. A phone face-up on a table showing the first two lines of every incoming message is a continuous, low-grade data leak, and it is a five-minute fix in device settings.

Where personal devices are involved, the clear screen requirements need to be consistent with what your BYOD policy already says, or staff receive two different instructions about the same handset.

Which ISO 27001 controls this supports

The primary control is A 7.7, but a clean desk policy provides evidence against several others: A 7.6 for working in secure areas, A 6.7 for remote working, A 5.10 for acceptable use, A 8.1 for user endpoint devices, and A 7.10 for storage media. It also underpins A 7.14 on secure disposal of equipment.

That spread is worth noting in your Statement of Applicability. A single short document that supports six controls is efficient, and pointing that out to an auditor demonstrates you understand the control set rather than having written a policy per line item. Our guide to the mandatory documents ISO 27001 requires explains which documents the standard genuinely demands and which are supporting evidence like this one.

Rolling out a clean desk policy without a revolt

The rollout kills more of these than the drafting does. Announce the rules on a Monday, run a sweep on the Tuesday and circulate a list of offenders, and you have taught the organisation that security is a compliance tax administered by people who do not do their job.

A sequence that works: fix the environment first, then announce, then sweep. Put the lockable storage in before you ask anyone to lock things away. Turn on pull printing before you write a rule about collecting print jobs. Order the confidential waste bins and place them where the printers actually are rather than where the floor plan says they should be.

Then announce with the reasoning attached. Staff comply with rules they understand and evade rules that arrive as edicts, and the reasoning here is easy to explain — a printed board pack left on a desk is readable by the cleaning contractor, the visiting supplier and anyone who walks past.

Give it a grace period of a few weeks before the first recorded walkthrough, and be visible about leadership following the same rules. An executive corner office with papers spread across it is the single most efficient way to communicate that a clean desk policy is optional.

How to evidence a clean desk policy

This is where a clean desk policy usually comes apart. The document exists, staff have read it, and there is nothing whatsoever to show the control operates.

Three artefacts fix that:

  • Periodic walkthroughs. A short recorded sweep — date, areas covered, findings, actions. Monthly is ample. The value is in recording the walkthroughs that found nothing as well as the ones that did.
  • Acknowledgements. Staff confirmation that they have read the policy, captured at induction and again when it materially changes.
  • Awareness content. Evidence the rules were communicated, not merely published to an intranet nobody visits.

Handle findings proportionately. The point of a walkthrough is to fix a pattern, not to discipline an individual, and a scheme that names people produces tidy desks on audit day and nothing else. Note what was found, note what changed, move on.

If you are preparing for certification more broadly, this control sits within the wider evidence expectations covered in our ISO 27001 certification guide.

Frequently asked questions

Is a clean desk policy mandatory for ISO 27001?

A separate document is not mandatory. Control A 7.7 requires that clear desk and clear screen rules are defined and enforced, so you need the rules to exist somewhere and to be demonstrably applied. A standalone policy is simply the easiest way to evidence both.

Does it apply to people working from home?

Yes. Control A 6.7 on remote working expects equivalent protection outside the office. In practice that means the same rules, plus providing lockable storage to anyone routinely handling confidential material at home.

What screen lock timeout should we set?

Base it on the space rather than picking one number for everyone. Short timeouts for shared and public areas, longer for controlled offices and home desks. Whatever you choose, document the reasoning — an auditor asking “why fifteen minutes?” wants to hear a risk rationale, not a shrug.

How do we enforce it without policing people?

Make compliance easy and make the walkthrough about the environment. Lockable storage within reach, pull printing, confidential waste bins where the printers are. Most breaches of a clean desk policy are logistics problems wearing a discipline costume.

Does it cover whiteboards and flipcharts?

It should. They are among the most common findings in a real audit walkthrough, particularly in meeting rooms used by visitors, and they are trivially easy to fix once the rule is written down.

Where to start

Write the screen half first — it is where the risk has moved and where most existing documents are thinnest. Then walk your own floor before an auditor does. One unannounced sweep will tell you more about whether the control operates than any amount of policy drafting.

Our ISO 27001 Toolkit includes a clear desk and clear screen policy alongside the physical security, remote working and acceptable use documents that reference it, mapped to the 2022 Annex A control set.

Control wording verified against ISO/IEC 27001 as published by ISO, August 2026.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.