ISO27001:2022 – A7.7
Clear desk and clear screen
In order to reduce the risks of unauthorised access, loss of and damage to information ISO27001 expects you to implement physical security at the macro and micro levels, and that’s where ISO 27001 – A7.7 comes into play.
This control demonstrates the intersection between physical and logical information security because you are required to implement rules that keep desks and screens free of information, both during and outside normal business hours.
What does ISO 27001 – A7.7 require?
The standard states that “Clear desk rules for papers and removable storage media and clear screen rules for information processing facilities shall be defined and appropriately enforced.” (A7.7 – Clear desk and clear screen).
Why is this required?
Because there are two aspects to this control, let’s separate them and see what challenges each one can bring.
Clear Desk
Leaving documents around on your desk or in your work area that contain confidential or personal information, creates opportunities for unauthorised access, loss or destruction. Anyone passing your desk can see what you’re working on, and could easily take a copy of the information (using a mobile phone), or simply remember what they’ve seen.
An organisation once found themselves in a difficult situation, when news of a large merger was due to be announced was leaked to the press. How was this information leaked? The CEO didn’t believe the Clear Desk Policy was something they needed to adhere to, and a report, detailing the merger had been left on their desk for review. It was free to be witnessed by anyone entering the office, from visiting executives to the cleaner, and their family.
A clear desk ensures that information is protected from prying eyes or casual observers. It also protects the information from unintentional damage and destruction too.
At the end of a very long day, a lawyer hadn’t cleared their desk of all the paper files and notes for the case they were working on. Preferring instead to leave the files there for the next day, they left it for the day, including a discarded cup of coffee.
That night, the cleaner, doing their job, tried to clean the exposed areas of the desk, working around the files, but accidentally knocked over the coffee cup. The accident not only destroyed several original documents, but in the rush to clean up, the Cleaner hurriedly grabbed as many files off the desk that they could. The lawyer returned to the office with a ‘tidy’ desk, a note of apology, and a pile of confusingly mixed files, some of which were no longer intelligible. The lawyer spent several days re-organising the files and collecting copies of the documents that had been destroyed.
Our question to you is; Who is to blame in this situation? And does it really matter?
Clear Screen
Sitting on a train, as we frequently do, we are often shocked (but not surprised) at how much information we see while watching people working on their mobile phones, tablets, or laptops. Sometimes travellers will leave their device and go to the toilets or buffet car for a snack, leaving their device unattended and unlocked.
What about you? Have you ever walked away from your desk, leaving your device unlocked, only to return to find that someone had used it without your knowledge? Maybe it was a business colleague, your partner, or maybe your children. Frustrating right?
But what happens if that someone is intent on doing you harm, or intent on accessing information that they shouldn’t?
When Kate Middleton announced her Cancer diagnosis, stories hit the headlines about how a nurse had attempted to access her medical records. We’re not sure why, although one can imagine that a news reporter had offered a cash incentive for ‘inside information’. The hospital had clearly considered other security controls, because someone received an alert when someone accessed her records.
But what would have happened if a nurse, authorised to access her records had simply left her device unlocked?
What the auditor is looking for
The auditor will look for evidence that both clear desk and clear screen security measures are in place. These measures typically include;
- Clear Desk and Clear Screen Policy
- Access Control Policies (A5.15 – Access Control)
- Information Classification Scheme (A5.12 – Classification of Information)
- Remote Working Policies and Procedures (A6.7 – Remote Working)
- Filing or storage facilities (e.g. lockable draws, to cabinets)
- Privacy screens on mobile devices
- Automatic Screen locking is in place (e.g. after 5 minutes of inactivity)
- Awareness, Education and Training for personnel
- Audit Reports
- Incident Logs
During the site tour the auditor will look for evidence that desks are clear, but also where desks are unattended, the screens are locked and display nothing which could expose your business to risk.
What do you need to do?
Noting that this ISO27001 control requires clear desk and clear screen rules to be defined, your first step is to document a policy which can be communicated to your business.
Treat these two aspects separately, but have one policy and start by explaining what you mean by ‘clear’. In our experience, people will want to know if they can still have family photos on their desks, books or plants! This policy should focus attention on confidential or personal information, and explain how this should be treated. You can refer back to your Classification Scheme that you developed when you considered Annex A Control A5.12 (Classification of Information)
Once your policy is in place, you will need to make people aware of what it contains. This should become part of your induction process, and ongoing training so that the message is continually (and consistently) provided.
You may also need to provide the facilities to store information securely, such as lockable draws or cabinets. But this depends on your budiness, space available and budget.
You may feel that as the world becomes less reliant on paper, a clear desk policy is no longer relevant, but you should think about other information that your personnel might come into contact with. For example, information provided by clients could be considered confidential, and personal information (such as passports, or other ID) will certainly need to be stored securely.
In terms of clear screen, you should work with your IT to implement automated locking of screens, so that when they are left unattended for a predefined amount of time, they will lock. This will require the user to enter a password, or PIN code to access the screen upon their return. The time that you set is up to you, but 5 minutes seems sensible and acceptable for most organisations.
If you have the budget, consider purchasing privacy screens for laptops and mobile devices. These restrict what can be seen on the screen from any casual on lookers.
One last note of caution; Don’t forget whiteboards in your meeting rooms. We have lost count of the times we’ve entered a meeting room with an auditor, only to see a whiteboard crammed with sales figures, or client specific information(!) Your policy should require personnel to clear the whiteboards at the end of a meeting. You might even instruct your cleaner to clear every whiteboard at the end of a working day. People will soon remember to take a photo of their notes if they know the notes will be gone the next day!
If you have printers in your offices, you should also make it standard practice to clear the printers of any papers. Make it standard practice to clear them of any papers at the end of each day and securely shred or destroy them using whatever approach you have decided upon.
Q & A
Do our desks need to be absent of all information?
Strictly speaking, no. Only that which could be considered confidential or personal needs to be cleared. But we believe it instils good habits and behaviour if your policy places expectations on people to put away client or personal data. Remembering our example above, the cleaner was only doing their job, but the ensuing ‘coffee drama’ caused significant delays and costs to the law firm.
Difficulty rating
We rate this a 1 out of 5 difficulty rating. This ISO27001 control isn’t difficult, but requires a little deeper thinking in terms of developing policies, procedures and providing the physical aspects of clear desk and screen.
More questions?
Remember that nothing in ISO27001 sits in isolation, so you should review our FAQ to gain answers to other aspects of the standard. Follow the links in this control to see the relationship in other controls, but if you’re still confused about this control, then please get in touch.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.
