Clean desk policy
A clean desk policy is an organisational security measure requiring staff to lock away sensitive documents, media and access credentials and to lock their screens whenever they leave their workspace, so that information cannot be read or taken by unauthorised people.
A clean desk policy defines how employees must leave their workspace when they step away from it. Its core rule is that paper files, handwritten notes, printouts, removable media, smartcards, keys and tokens are never left in the open but stored in lockable furniture. It is normally paired with a clear screen rule: automatic screen locking after a short period of inactivity, manual locking when leaving the desk, and secure release printing so that confidential documents do not sit unattended in an output tray. The measure addresses a risk that technical controls cannot cover — information simply being seen, photographed or taken by visitors, service providers, cleaning staff or colleagues who have no need to know.
The control is firmly anchored in the relevant standards. ISO/IEC 27001:2022 lists it in Annex A as control 7.7, "Clear desk and clear screen", and ISO/IEC 27002:2022 sets out how to implement it. The German BSI IT-Grundschutz framework covers the tidy workspace in its organisational and infrastructure modules, including office rooms and home workplaces. From a data protection perspective it is an organisational measure within the meaning of Article 32(1) GDPR, because it protects the confidentiality of personal data at the point where it is actually handled. For entities in scope of the NIS2 Directive and its German transposition into the BSIG, workplace hygiene and personnel security form part of the risk management measures required under Article 21 of the Directive.
A policy only becomes effective once it is specific and verified. It works best when tied to the organisation's information classification scheme: the higher the protection level, the stricter the storage requirement — from "not visible in the open" through "lockable pedestal" to "steel cabinet or safe". A usable policy names responsibilities, screen lock timeouts, the handling of whiteboards and flip charts, disposal through secure bins or shredders of the appropriate DIN 66399 security level, and rules for remote work in homes, trains, aircraft and coworking spaces. It must be supported by awareness training, unannounced evening walkthroughs as evidence of effectiveness, and a documented response to breaches; without such records the control rarely survives an internal audit or an ISO 27001 certification assessment.
Legal Basis
ISO/IEC 27001:2022 Annex A 7.7 and ISO/IEC 27002:2022 control 7.7; Article 32(1) GDPR; BSI IT-Grundschutz (organisation and office/home workplace modules); NIS2 Directive (EU) 2022/2555 Article 21 in conjunction with the German BSIG
Practical Example
A mid-sized automotive supplier is preparing for ISO 27001 certification. During an evening walkthrough, the information security officer finds open application folders in the HR open-plan office, an unlocked pedestal containing salary lists, two unlocked workstations, and a termination letter lying in the corridor printer. She introduces a clean desk and clear screen policy linked to the company's four-level information classification scheme, equips the department with lockable pedestals and secure disposal bins, switches the printers to badge-released follow-me printing, and sets the screen lock to five minutes via group policy. The rules are explained in an awareness session and then checked quarterly through spot-check evening walkthroughs with anonymised reports. Those reports later serve the auditor as evidence of effectiveness for control 7.7 and, at the same time, as proof of the organisational measures required by Article 32 GDPR.