# Clear desk and clear screen policy

Source: https://aestech.com.au/policy-templates/#clear-desk-and-clear-screen-policy
Markdown URL: https://aestech.com.au/policy-templates/clear-desk-and-clear-screen-policy.md

Use for ISO 27001 A.7.7, physical protection of papers and screens, printing controls, and office and visitor area practices.

Frameworks: ISO 27001

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines the rules for keeping papers, removable media and screens free of exposed information when unattended, so that Confidential and Restricted information cannot be read, photographed or removed by unauthorised people.

2. Scope
This policy applies to all staff, contractors and visitors in company offices, home offices, co-working spaces and any other location where company information is displayed or handled physically.

3. Policy statements
- Screens must lock automatically after no more than [10] minutes of inactivity, and staff must lock screens manually with [shortcut] whenever leaving a device unattended, even briefly.
- Desks must be cleared of papers, notebooks and removable media containing Internal, Confidential or Restricted information at the end of each day and whenever leaving the desk for an extended period. Such material must be stored in [lockable drawers or cabinets].
- Passwords, access codes and keys must never be written on notes, whiteboards or visible surfaces.
- Printing of Confidential or Restricted documents must be collected immediately. Where available, [secure print release] must be used. Uncollected print jobs found at printers must be handed to [role] or destroyed.
- Paper and media requiring disposal must go into [locked shred bins or a cross-cut shredder], never general waste or recycling.
- Whiteboards and flip charts must be erased after meetings that involve Confidential information, and meeting room screens disconnected or cleared before leaving.
- In visitor areas and meeting rooms visible to visitors, no Confidential material may be left on display. Visitors must be escorted and must not be left alone in work areas.
- Screens in reception, shared or public-facing positions must be angled or fitted with privacy filters so that passers-by cannot read them.

4. Roles and responsibilities
- Staff: follow clear desk and clear screen practices at all locations.
- Managers: address repeated non-compliance within their teams.
- [Office manager or security lead]: provide lockable storage, shred bins and privacy filters, and run periodic walkthroughs.

5. Procedures
- [Role] performs a documented clear desk walkthrough at least [quarterly], recording findings and corrective actions.
- Findings such as exposed documents or unlocked screens are logged in [ticketing system] and raised with the individual and their manager.
- Screen lock timeouts are enforced centrally through [device management tool].

6. Evidence and records
Keep walkthrough checklists and findings, corrective action records, device management screen lock configuration reports, shredding or secure destruction certificates and policy acknowledgements.

7. Review
Owner: [role]. Reviewed at least annually and after office moves or repeated findings.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md