Most information leaks don’t involve hacking.
They involve what was left behind.
Annex A 7.7 exists to ensure organisations protect sensitive information on desks, screens, and shared workspaces, reducing the risk of unauthorised access, observation, loss, or misuse.
This control targets one of the simplest — and most overlooked — causes of data exposure.

Annex A 7.7 of ISO 27001:2022 focuses on clear desk and clear screen practices.
At a practical level, this means:
The control does not mandate a single policy format. It expects organisations to define and apply clear rules that reduce casual and opportunistic exposure.
Unattended workspaces create easy opportunities for:
Common examples include:
Annex A 7.7 addresses these everyday risks by promoting disciplined, repeatable handling of information, regardless of role or location.
This control replaces ISO 27001:2013 Annex A 11.2.9 and reflects modern working practices, including mobile devices and open-plan environments.
A pragmatic approach to Annex A 7.7 typically includes the following elements.
Organisations should define what “clear” means in practice, including:
Clarity prevents inconsistent interpretation.
Physical materials containing sensitive information should be protected, for example by:
Paper remains a common source of exposure.
Screens should not display sensitive information when unattended.
Organisations typically apply:
Unattended screens are one of the easiest access points for misuse.
Printers and shared devices introduce additional risk.
Organisations should consider:
Printed material is often forgotten — and easily seen.
Sensitive information can be exposed unintentionally.
Annex A 7.7 supports defining rules for:
Visibility risk increases in meetings and public or shared environments.
When information is no longer required, it should be disposed of securely.
This may include:
Clear desks are ineffective without secure disposal.
When desks, rooms, or facilities are vacated, organisations should ensure:
End-of-use scenarios are frequently overlooked.
Annex A 7.7 does not require:
It does require organisations to:
This control works best when normalised, not policed.
Most breaches here are accidental — prevention is behavioural.
Annex A 7.7 is about eliminating easy wins for unauthorised access.
When clear desk and clear screen practices are applied effectively:
Sophisticated attacks get attention.
Annex A 7.7 prevents the simple ones that succeed far too often.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today