ISO 27002 Control 7.7: Strengthening Security with Clear Desk & Screen Practices
When an employee leaves his/her workstation unattended, sensitive information contained in digital and physical materials on his workspace will be exposed to a heightened risk of unauthorised access, loss of confidentiality, and damage.
For instance, if an employee uses a customer relationship management tool that processes health records and leaves his/her computer unattended during a lunch break, malicious parties may capitalise on this opportunity to steal and misuse sensitive health data.
Control 7.7 addresses how organisations can design and enforce clear desk and clear screen rules to protect and maintain the confidentiality of sensitive information on digital screens and on papers.
Purpose on Control 7.7
Control 7.7 enables organisations to eliminate and/or mitigate the risks of unauthorised access, use, damage, or loss of sensitive information on screens and on papers located in employee workstations when employees are not present.
Attributes Table of Control 7.7
Control 7.7 is a preventive type of control that requires organisations to maintain the confidentiality of information assets by describing and enforcing clear desk and clear screen rules.
| Control Type | Information Security Properties | Cybersecurity Concepts | Operational Capabilities | Security Domains |
|---|---|---|---|---|
| #Preventive | #Confidentiality | #Protect | #Physical Security | #Protection |
ISO 27001 made easy
An 81% Headstart from day one
We’ve done the hard work for you, giving you an 81% Headstart from the moment you log on. All you have to do is fill in the blanks.
Ownership of Control 7.7
Considering that Control 7.7 requires organisations to adopt and implement an organisation-wide clear desk and clear screen policy, information security officers should be responsible for production, maintenance and enforcement of clear desk and clear screen rules that apply across the entire organisation.
General Guidance on Compliance
Control 7.7 highlights that organisations should create and enforce a topic-specific policy that sets out clear desk and clear screen rules.
Furthermore, Control 7.7 lists seven specific requirements that organisations should take into account when establishing and enforcing clear desk and clear screen rules:
- Sensitive or critical information assets stored on digital or physical items should be locked securely when they are not in use or when the workstation hosting those materials is vacated. For example, items such as paper records, computers, and printers should be stored in secure furniture such as a locked or password-protected cabinet or drawer.
- Devices used by employees such as computers, scanners, printers, and notebooks should be protected via security mechanisms such as key locks when they are not used or when they are left unattended.
- When employees vacate their workspace and leave their devices unattended, they should leave their devices logged off and the reactivation of the device should be only via a user authentication mechanism. Furthermore, automatic time-out and log-out features should be installed on all end-point employee devices such as computers.
- Printers should be designed in a way that print-outs are collected immediately by the person(originator) who printed the document. Furthermore, a strong authentication mechanism should be in place so that only the originator is allowed to collect the printout.
- Physical materials and removable storage media containing sensitive information should be kept secure at all times. When they are no longer needed, they should be disposed of through a secure mechanism.
- Organisations should create rules for the display of pop-ups on screens and these rules should be communicated to all relevant employees. For example, e-mail and messaging pop-ups can contain sensitive information and if they are displayed on the screen during a presentation or in a public space, this may compromise the confidentiality of sensitive information.
- Sensitive or critical information displayed on whiteboards should be erased when they are no longer needed.
Supplementary Guidance – Control 7.7
Control 7.7 cautions organisations against risks arising out of vacated facilities. When an organisation vacates a facility, physical and digital materials previously stored in that facility should be securely removed so that sensitive information is not left insecure.
Therefore, control 7.7 requires organisations to establish procedures for the vacation of facilities so that all sensitive information assets housed in that facility are securely disposed of. These procedures may include carrying out a final sweep so that no sensitive information is left unprotected.
Manage all your compliance, all in one place
ISMS.online supports over 100 standards and regulations, giving you a single platform for all your compliance needs.
Changes and Differences From ISO 27002:2013
27002:2022/7.7 replaces 27002:2013/(11.2.9)
There are two significant differences between the 2022 and the 2013 versions.
- 2022 version does not refer to criteria to consider when establishing and implementing clear desk and clear screen rules.
In contrast to the 2022 version, the 2013 version explicitly stated that organisations should consider organisation-wide information classification levels, legal & contractual requirements, and the types of risks facing the organisation when establishing a clear desk and clear screen policy.
The ISO 27002:2022 version, however, does not refer to these elements.
- 2022 version introduces new and more comprehensive requirements for the clear desk and clear screen rules.
In contrast to the 2013 version, the 2022 version sets out the following requirements that organisations should consider when establishing clear desk and clear screen rules.
- Organisations should create specific rules on pop-up screens to maintain the confidentiality of sensitive information.
- Sensitive information written on whiteboards should be removed when they are no longer needed.
- Employee endpoint devices such as computers should be protected with key locks when they are not used or when they are left unsupervised.
New ISO 27002 Controls
| ISO/IEC 27002:2022 Control Identifier | ISO/IEC 27002:2013 Control Identifier | Control Name |
|---|---|---|
| 5.7 | NEW | Threat intelligence |
| 5.23 | NEW | Information security for use of cloud services |
| 5.30 | NEW | ICT readiness for business continuity |
| 7.4 | NEW | Physical security monitoring |
| 8.9 | NEW | Configuration management |
| 8.10 | NEW | Information deletion |
| 8.11 | NEW | Data masking |
| 8.12 | NEW | Data leakage prevention |
| 8.16 | NEW | Monitoring activities |
| 8.23 | NEW | Web filtering |
| 8.28 | NEW | Secure coding |
| ISO/IEC 27002:2022 Control Identifier | ISO/IEC 27002:2013 Control Identifier | Control Name |
|---|---|---|
| 6.1 | 07.1.1 | Screening |
| 6.2 | 07.1.2 | Terms and conditions of employment |
| 6.3 | 07.2.2 | Information security awareness, education and training |
| 6.4 | 07.2.3 | Disciplinary process |
| 6.5 | 07.3.1 | Responsibilities after termination or change of employment |
| 6.6 | 13.2.4 | Confidentiality or non-disclosure agreements |
| 6.7 | 06.2.2 | Remote working |
| 6.8 | 16.1.2, 16.1.3 | Information security event reporting |
| ISO/IEC 27002:2022 Control Identifier | ISO/IEC 27002:2013 Control Identifier | Control Name |
|---|---|---|
| 7.1 | 11.1.1 | Physical security perimeters |
| 7.2 | 11.1.2, 11.1.6 | Physical entry |
| 7.3 | 11.1.3 | Securing offices, rooms and facilities |
| 7.4 | NEW | Physical security monitoring |
| 7.5 | 11.1.4 | Protecting against physical and environmental threats |
| 7.6 | 11.1.5 | Working in secure areas |
| 7.7 | 11.2.9 | Clear desk and clear screen |
| 7.8 | 11.2.1 | Equipment siting and protection |
| 7.9 | 11.2.6 | Security of assets off-premises |
| 7.10 | 08.3.1, 08.3.2, 08.3.3, 11.2.5 | Storage media |
| 7.11 | 11.2.2 | Supporting utilities |
| 7.12 | 11.2.3 | Cabling security |
| 7.13 | 11.2.4 | Equipment maintenance |
| 7.14 | 11.2.7 | Secure disposal or re-use of equipment |
How ISMS.online Helps
ISO 27002 implementation is simpler with our step-by-step checklist that guides you through the whole process. Your complete compliance solution for ISO/IEC 27002:2022.
- Up to 81% progress from when you log in
- Simple and total compliance solution
Get in touch today to book a demo.








