SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.7.7Clear desk and clear screen

Require staff to keep sensitive papers off desks and lock screens when away, so information is not left exposed to passersby.

Mapping at a glance
A.7.7Clear desk and clear screenISO/IEC 27001:2022

A.7.7 is covered by 1 Sekit CSF control. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

In practice

This is one of the cheapest controls to implement and one of the easiest to fail on a walkthrough, because it depends entirely on daily habit rather than a system. Auditors walk the floor at the end of the day or during a break and look for unattended unlocked screens and papers with client names left on desks. A written rule with no reinforcement rarely survives contact with a busy week, so the practices that hold up are ones repeated at onboarding and again periodically, not stated once in a handbook nobody rereads.

Common gaps

Screens were found unlocked and unattended during a walkthrough, even though the acceptable use policy states a clear screen rule.
New hires are told about the clear desk rule once during onboarding but it is never mentioned again, and compliance visibly drops a few months in.
Printed client documents were left on a desk overnight in an open-plan office visible from the reception area.

Questions your auditor will ask

How do you make sure staff lock their screens when they step away, not only during onboarding week?
Locking the screen when leaving a workstation is reinforced through onboarding and periodic reminders, not left as a one-time rule.
Is compliance with the clear desk and clear screen rule ever checked?
A walkthrough during or after work hours checks for unlocked screens and papers left on desks, rather than relying on the policy alone.
What happens when a sensitive document is left visible on a desk?
The finding is raised with the individual and treated as a habit gap to correct through a reminder, not a one-off exception to ignore.

Where regulation demands it

NIS2 art. 8.1 requires basic cyber hygiene practices among staff, including locking screens and keeping sensitive papers off desks when unattended.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.7.7?”
Also via MCP, free with account