---
title: "ISO 27001: 2022 A.7.7 Clear desk and clear screen"
description: "This article provides additional information on how you can meet the requirement for the ISO 27001: 2022 A.7.7 Clear desk and clear screen."
---

[Skip to content](https://knowledge.adoptech.co.uk/iso-27001-2022-a.7.7-clear-desk-and-clear-screen#main-content)

[![Adoptech-logo-GreyWithoutStrapline-1.png\]](https://knowledge.adoptech.co.uk/hs-fs/hubfs/Adoptech-logo-GreyWithoutStrapline-1.png?height=39&name=Adoptech-logo-GreyWithoutStrapline-1.png)](https://knowledge.adoptech.co.uk/?hsLang=en)

Open main navigation

Close main navigation

 Adoptech Help Centre

- There are no suggestions because the search field is empty.

1. [Knowledge base](https://knowledge.adoptech.co.uk/?hsLang=en)
2. [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en)
3. [ISO 27001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-27001)

# ISO 27001: 2022 A.7.7 Clear desk and clear screen

## This article provides additional information on how you can meet the requirement for the ISO 27001: 2022 A.7.7 Clear desk and clear screen.

### **ISO 27001: 2022 Control Description**

Clear desk rules for papers and removable storage media and clear  screen rules for information processing facilities shall be defined and appropriately enforced.

### Purpose

To minimise the risks of unauthorised access, loss, and damage to information left on desks, screens, and other accessible locations during and outside normal working hours.

### **Guidance on implementation**

The organisation should establish and communicate a topic-specific policy regarding clear desk and clear screen practices to all relevant interested parties.

The following guidelines should be considered:

a) Securing sensitive or critical business information (e.g., on paper or electronic storage media) by locking it away in a safe, cabinet, or other secure furniture when not in use, especially when the workspace is unattended.

b) Protecting user endpoint devices with key locks or other security measures when they are not in use or left unattended.

c) Logging off user endpoint devices or activating screen and keyboard locking mechanisms controlled by user authentication when devices are unattended. All computers and systems should be configured with automatic timeout or logout features.

d) Ensuring that individuals collect printouts from printers or multi-function devices immediately after printing. Consider using printers with authentication functions so that documents are only released when the originator is present at the device.

e) Securely storing documents and removable storage media containing sensitive information, and disposing of them securely when no longer needed through appropriate disposal mechanisms.

f) Establishing and communicating rules and guidance for configuring screen pop-ups (e.g., disabling new email and messaging notifications during presentations, screen sharing, or when in public areas, where possible).

g) Erasing sensitive or critical information from whiteboards and other display surfaces once it is no longer required.

The organisation should have procedures in place for vacating facilities, including conducting a final inspection before leaving to ensure that no organisational assets are left behind (e.g., documents that may have fallen behind drawers or furniture).

- [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#main-content)

    - [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#getting-started)
    - [Accounts & Billing](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#accounts-billing)
- [FAQ's on Adoptech](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#main-content)

    - [Frameworks](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#frameworks)
    - [Policies & Documents](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#policies-documents)
    - [Risk Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#risk-management)
    - [Supplier Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#supplier-management)
    - [Audit Preparation](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#audit-preparation)
    - [Trust Centre](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#trust-centre)
    - [User Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#user-management)
- [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#main-content)

    - [ISO 27001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-27001)
    - [ISO 42001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-42001)
    - [Cyber Essentials](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#cyber-essentials)
    - [CAF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#caf)
    - [PCI-DSS](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#pci-dss)
    - [SOC2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#soc2)
    - [Data Privacy (GDPR)](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#data-privacy-gdpr)
    - [DORA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#dora)
    - [ISO 9001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-9001)
    - [ISO 22301](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-22301)
    - [ISO 14001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-14001)
    - [NIST 800-53](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-800-53)
    - [NIST-CSF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-csf)
    - [NIS2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nis2)
    - [ISO 20000-1](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-20000-1)
    - [HIPAA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#hipaa)
- [Integrations](https://knowledge.adoptech.co.uk/integrations?hsLang=en#main-content)

    - [Cloud Infrastructure](https://knowledge.adoptech.co.uk/integrations?hsLang=en#cloud-infrastructure)
    - [Identity & Access](https://knowledge.adoptech.co.uk/integrations?hsLang=en#identity-access)
    - [DevOps & Code](https://knowledge.adoptech.co.uk/integrations?hsLang=en#devops-code)
    - [Project Management](https://knowledge.adoptech.co.uk/integrations?hsLang=en#project-management)
    - [HR & People Systems](https://knowledge.adoptech.co.uk/integrations?hsLang=en#hr-people-systems)
    - [Security & Devices](https://knowledge.adoptech.co.uk/integrations?hsLang=en#security-devices)
    - [Communication & Collaboration](https://knowledge.adoptech.co.uk/integrations?hsLang=en#communication-collaboration)
- [Legal & Regulations](https://knowledge.adoptech.co.uk/legal-regulations?hsLang=en)
- [Security Guidance](https://knowledge.adoptech.co.uk/security-guidance?hsLang=en)
- [Troubleshooting](https://knowledge.adoptech.co.uk/troubleshooting?hsLang=en)

[![Chill listening crop-3](https://knowledge.adoptech.co.uk/hs-fs/hubfs/adoptech-logo-1.png?width=209&height=54&name=adoptech-logo-1.png "Chill listening crop-3")](https://adoptech.co.uk/)

<https://uk.linkedin.com/company/adoptech>

Copyright © 2026, Adoptech Ltd.