ISO 27002:2022
Physical controls – ISO 27002:2022

ISO 27002:2022 7.7: Clear desk and clear screen

Requires defined and enforced rules for clearing papers and removable storage media from desks, and for clearing the screens of facilities used to process information.

What else in your programme already covers this

This control maps to 48 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 5 controls

  • AC-11 Device Lock
  • AC-11(1) Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image
  • MP-2 Media Access
  • MP-4 Media Storage
  • PE-5 Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output

FedRAMP Moderate · 5 controls

  • AC-11 Device Lock
  • AC-11(1) Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image
  • MP-2 Media Access
  • MP-4 Media Storage
  • PE-5 Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output

NIST SP 800-53 Rev 5 · 5 controls

  • AC-11 Device Lock
  • AC-11(1) Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image
  • MP-2 Media Access
  • MP-4 Media Storage
  • PE-5 Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output
  • AC-11 Device Lock
  • AC-11(1) Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image
  • MP-2 Media Access
  • MP-4 Media Storage
  • PE-5 Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output
  • ISM-0161 IT equipment and media are secured when not in use.
  • ISM-0164 Unauthorised people are prevented from observing systems, in particular workstation displa
  • ISM-2012 Systems are configured with a screen lock that: - activates after a maximum of 15 minutes

CIS Controls v8 · 2 controls

  • CIS-14.4 Train Workforce on Data Handling Best Practices
  • CIS-4.3 Configure Automatic Session Locking on Enterprise Assets

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

C5 (Germany) · 1 control

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy

ISO 27001:2022 · 1 control

  • 7.7 Clear desk and clear screen

ISO 27018 · 1 control

  • A.10.3 Restriction of creation of hardcopy material

ISO 27018:2019 · 1 control

  • 11.2.9 Clear desk and clear screen policy

ISO/IEC 27018:2019 · 1 control

  • A.10.3 Restriction of creation of hardcopy material
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk

PCI DSS 4.0 · 1 control

  • 8.2.8 Session idle timeout

SOC 2 · 1 control

  • SOC2-CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Physical controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 7.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 48 it maps to, and the evidence behind each claim, over MCP and REST.