This is one of the cheapest controls to implement and one of the easiest to fail on a walkthrough, because it depends entirely on daily habit rather than a system. Auditors walk the floor at the end of the day or during a break and look for unattended unlocked screens and papers with client names left on desks. A written rule with no reinforcement rarely survives contact with a busy week, so the practices that hold up are ones repeated at onboarding and again periodically, not stated once in a handbook nobody rereads.
Common gaps
Screens were found unlocked and unattended during a walkthrough, even though the acceptable use policy states a clear screen rule.
New hires are told about the clear desk rule once during onboarding but it is never mentioned again, and compliance visibly drops a few months in.
Printed client documents were left on a desk overnight in an open-plan office visible from the reception area.
Questions your auditor will ask
How do you make sure staff lock their screens when they step away, not only during onboarding week?
Locking the screen when leaving a workstation is reinforced through onboarding and periodic reminders, not left as a one-time rule.
Is compliance with the clear desk and clear screen rule ever checked?
A walkthrough during or after work hours checks for unlocked screens and papers left on desks, rather than relying on the policy alone.
What happens when a sensitive document is left visible on a desk?
The finding is raised with the individual and treated as a habit gap to correct through a reminder, not a one-off exception to ignore.
Where regulation demands it
NIS2 art. 8.1 requires basic cyber hygiene practices among staff, including locking screens and keeping sensitive papers off desks when unattended.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.