A Clear Desk and Clear Screen Policy requires employees to secure physical documents and lock their screens whenever they step away from their workstation. On the surface, it sounds almost too simple to need a formal policy — but the physical environment is one of the most underestimated vectors for information exposure in any organization. A financial report left on a desk, a medical record visible on an unattended screen, or a whiteboard covered in strategic plans photographed by a visitor can cause the same damage as a sophisticated cyberattack, and often with far less effort from the attacker.

Physical information security often receives less attention than digital security because breaches of this type are harder to detect. There is no system log of a passerby reading a document on your desk. There is no alert when a visitor photographs a screen. The consequence is that organizations that invest heavily in firewalls, encryption, and access controls can still be compromised through the simplest possible means — an unlocked screen, a stack of papers, or a conference room whiteboard.

What Is a Clear Desk and Clear Screen Policy?

A Clear Desk and Clear Screen Policy is a set of procedural requirements governing the physical handling of information. It specifies that employees must lock their computer screens when stepping away from their desks, secure physical documents when not actively using them, store sensitive materials in locked cabinets or drawers at the end of the workday, and avoid leaving printed materials in shared spaces such as printers, copiers, or conference rooms.

The policy applies to all employees and contractors who handle company information in a physical workspace — including traditional offices, shared coworking spaces, home offices, and any location where company work is conducted. It also applies to visitors and shared spaces: conference rooms used for sensitive discussions, reception areas where client-facing information may be visible, and server rooms or secure areas where equipment should not be left unlocked or unattended.

Core Requirements of the Policy

Screen Locking

Employees should lock their computer screens whenever they step away, even for a brief period. The manual lock — Windows key + L on Windows, Control + Command + Q on macOS — should be a habitual action. In addition, all workstations should be configured with automatic screen lock after a period of inactivity. The timeout should be short: five to ten minutes is the typical standard in security-conscious organizations. A fifteen-minute or longer timeout is generally too long for environments handling sensitive data, because an unattended workstation can be accessed, photographed, or manipulated in a matter of seconds.

Physical Document Security

Paper documents containing sensitive or confidential information should not be left on desks unattended. When an employee steps away from their work area — for a meeting, a break, or the end of the day — documents should be placed face-down or stored in a locked drawer or cabinet. At the end of each workday, desks should be cleared of all sensitive materials. This ‘clean desk at end of day’ requirement prevents cleaning staff, after-hours visitors, or early-arriving colleagues from viewing information they are not authorized to see.

Printing and Copying

Shared printers and copiers are a chronic source of document exposure. Employees routinely send a document to print and then retrieve it minutes later — or forget about it entirely. In that window, any passerby can read the document. Organizations handling sensitive data should consider implementing print release controls, where a print job is held in a queue and released only when the employee physically authenticates at the printer. At minimum, the policy should require employees to retrieve printed documents immediately and prohibit leaving documents at printers, copiers, fax machines, or scanners.

Whiteboards and Displays in Shared Spaces

Conference rooms and shared work areas frequently contain whiteboards or displays showing information from meetings. Organizational charts, financial projections, system architecture diagrams, client names, and strategic plans routinely end up on whiteboards that are then left visible after the meeting ends. The policy should require that whiteboards be erased at the conclusion of any meeting, that digital displays be disconnected or turned off when the room is unoccupied, and that no sensitive information be written on surfaces visible from public areas such as hallways, lobbies, or exterior windows.

Visitor Areas and Reception Security

Reception desks, waiting areas, and entry points create specific risks because they are accessible to individuals who have not been vetted or trained on the organization’s security expectations. Documents at reception desks, screens visible from public areas, and information posted on walls or notice boards can all be observed by visitors. The policy should establish that no sensitive information is stored or displayed in publicly accessible areas, that reception screens are positioned to prevent visitor viewing, and that any documents in visitor-accessible areas are strictly limited to public-facing materials.

Remote and Coworking Environments

Remote workers and employees who work in coworking spaces or public locations such as coffee shops face heightened physical security risks. Shoulder surfing — someone reading your screen while sitting nearby — is a real and well-documented attack vector. The policy should require employees working in public or shared spaces to use privacy screens (physical screen filters that limit the viewing angle), position their screens away from areas of foot traffic, lock screens immediately when stepping away from a workstation, and avoid displaying or handling sensitive documents in environments where unauthorized individuals may be able to observe them.

Why This Policy Matters: Real-World Scenarios

It is worth grounding this policy in concrete examples, because the risks can seem abstract until you consider how easily they occur. A healthcare employee steps away from their workstation for five minutes without locking the screen. A patient walking past the nursing station can see another patient’s medication records on the screen. That is a HIPAA violation with real regulatory consequences. A financial services employee leaves a deal term sheet on their desk while taking a client call in a conference room. A cleaning crew member, a new employee, or a visitor with authorized access to that floor can read the terms of a transaction that has not yet been announced publicly.

A software company has a strategy session in a conference room. The team creates detailed architecture diagrams and competitive analysis on the whiteboard, then leaves for lunch without erasing it. A vendor who has a meeting in the same room an hour later photographs the whiteboard with their phone. A remote employee joins a video call from a coffee shop, sharing their screen to show a draft client proposal. The person seated behind them can read the client’s name, budget, and project details. These are not hypothetical scenarios — they are the kinds of incidents that appear in breach investigations and disciplinary proceedings.

Regulatory and Compliance Drivers

ISO 27001 Annex A.11.2.9

ISO 27001, the international standard for information security management, includes a specific control for clear desk and clear screen practices in Annex A.11.2.9. The control requires organizations to define and implement a clear desk policy for papers and removable storage media, and a clear screen policy for information processing facilities. Organizations pursuing ISO 27001 certification will need to demonstrate that this policy exists, that it is communicated to employees, and that compliance is monitored.

SOC 2

SOC 2 audits assess the design and operating effectiveness of controls across five Trust Services Criteria. Physical security controls, including clear desk and clear screen practices, are relevant to the Common Criteria around logical and physical access controls. Auditors will ask whether physical security policies exist and whether there is evidence of employee awareness and compliance. For organizations in SOC 2 audits, having a documented policy and training records is a baseline requirement.

HIPAA Physical Safeguards

HIPAA’s Security Rule requires covered entities and business associates to implement physical safeguards to protect electronic protected health information (ePHI). The workstation use standard (45 CFR §164.310(b)) requires covered entities to implement policies governing the proper functions to be performed on workstations, how those functions are to be performed, and the physical attributes of the surroundings of a workstation. A clear screen policy directly addresses this requirement by establishing standards for workstation use that protect ePHI from unauthorized viewing.

PCI DSS

The Payment Card Industry Data Security Standard requires organizations that handle cardholder data to maintain physical security controls that prevent unauthorized access to cardholder data environments. PCI DSS Requirement 9 covers physical security, including controls over access to workstations and the handling of printed cardholder data. Clear desk and clear screen practices support compliance with these requirements in any organization that processes, stores, or transmits payment card information.

Common Implementation Mistakes

Auto-Lock Timeouts That Are Too Long

A screen lock timeout of 15 or 30 minutes — which is common in default operating system configurations — is not a security control. It is an inconvenience to attackers at best. In environments handling sensitive data, the timeout should be set to five minutes or less as a technical baseline, with a policy requiring manual locking whenever an employee steps away regardless of the timeout setting. IT should enforce these timeouts through group policy or device management tools so individual employees cannot override them.

Conference Room Whiteboards Left Uncleaned

This is one of the most consistent failures in organizations that have a clear desk policy in name but not in practice. Strategy sessions, architectural design discussions, and client planning meetings generate whiteboard content that is then left for hours or days. Adding a simple procedural requirement — the meeting organizer is responsible for ensuring the whiteboard is erased before the room is vacated — and reinforcing it through manager check-ins and periodic audits can close this gap quickly.

Remote Workers Exempting Themselves from the Policy

There is a common but incorrect assumption that clear desk requirements apply only in the office. Remote employees handling sensitive data are subject to the same physical security risks — and in some ways greater ones, given that home environments are less controlled. The policy must explicitly state that it applies to all work locations, including home offices and public spaces, and remote worker training should address the specific challenges of maintaining physical security outside the traditional office.

No Verification or Audit Mechanism

A policy without any verification mechanism becomes aspirational rather than operational. Periodic clean desk audits — a simple walk-through by a manager or security team member at the end of the day to check for unattended documents and unlocked screens — are an effective and low-cost way to reinforce the policy. Audit findings should be documented and shared with employees as a learning tool, not just a compliance checkbox.

Building and Maintaining the Policy

Ownership of the clear desk and clear screen policy typically sits with the facilities manager, CISO, or IT security team, depending on the organization’s structure. It should be introduced during employee onboarding alongside related physical security and information handling policies. Regular reminders — a brief message at the end of a company meeting, a note in an internal newsletter, or a poster in the office — help maintain awareness without requiring extensive training infrastructure.

Technical controls should support the policy wherever possible. Automatic screen lock enforcement through MDM or group policy removes the dependency on employee behavior for the screen-locking component. Print release controls at printers eliminate the unattended-document risk without relying on employees remembering to retrieve documents promptly. When technical controls are in place, the policy focuses on the remaining behaviors that technology cannot automate: clearing desks, erasing whiteboards, and exercising judgment in public spaces.

How It Connects to the Broader Policy Library

The Clear Desk and Clear Screen Policy sits within the Physical and Environmental Security Policy as a specific subset of physical security requirements, or it may be published as a standalone document that cross-references the broader physical security framework. It connects directly to the Information Classification Policy, because the level of care required for a given document depends on its classification — a publicly available product brochure does not require the same physical protection as a client contract or personnel file.

The Acceptable Use Policy establishes the behavioral norms for technology use and overlaps with the screen locking requirement. The Remote Work Policy addresses the specific challenges of maintaining security standards outside the office and should reference clear desk requirements as part of the home office security expectations. Together, these policies address the full spectrum of information handling — digital and physical — that an employee encounters across all work contexts.

See Also