Rules requiring clear desks for papers and removable media and clear screens for processing facilities are to be defined and suitably enforced. Purpose: lower the risk of unauthorized access to, loss of or damage to information left on desks, screens and other reachable places, in and outside working hours. Guidance: publish a topic-specific policy on clear desks and clear screens to relevant parties and consider: locking away sensitive or critical information on paper or media, preferably in a safe or lockable cabinet, when not needed and especially when the office is empty; securing user endpoint devices with key locks or similar when unused or unattended; logging off unattended devices or protecting them with an authenticated screen and keyboard lock, and configuring timeouts or automatic logout on all computers and systems; having people collect printouts immediately and using printers that release jobs only after the originator authenticates at the device; storing sensitive documents and media securely and disposing of them securely when no longer needed; setting rules for screen pop-ups, such as turning off email and messaging notifications during presentations, screen sharing or in public; and wiping sensitive information from whiteboards and other displays after use. When facilities are vacated, a final sweep should confirm nothing is left behind, such as documents that have fallen behind drawers or furniture.
This control maps to 35 controls across 16 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 7.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 35 it maps to, and the evidence behind each claim, over MCP and REST.