A clean desk policy is a workplace rule requiring staff to clear confidential papers from their desks, lock their screens and put away removable media whenever they leave the desk — during the day and at close of business. It is usually paired with a clear screen rule (lock your computer every time you step away), which is why standards like ISO 27001 treat them as one control: clear desk and clear screen. The point is not tidiness. It is that confidential information — client lists, payslips, contracts, unlocked systems — must never be exposed to someone who should not see it.
TL;DR
- Clean desk means papers filed or shredded, screens locked and USBs stored away every time a desk is left.
- ISO 27001 treats clear desk and clear screen as a formal control, so auditors and insurers ask for evidence.
- Training that sticks rehearses the leaving-the-desk moment, not just the memo.
- The visitor test — what is visible from where a stranger stands — makes the risk concrete.
- Spot checks with a simple measure beat an annual reminder every time.
Why a clean desk policy matters
A policy on paper documents and locked screens is the physical sibling of phishing training. Both address the same truth: controls fail at the point of human contact. The Office of the Australian Information Commissioner reported that human error caused 37% of all data breaches in the first half of 2025, up from 29% in the previous period — before counting the criminal attacks that started with someone being careless. An unlocked screen in a shared office, a payslip left in the printer tray or a client contact list visible from reception is a breach waiting for a visitor, a cleaner or a contractor with a phone.
Some industries do not get a choice. ISO 27001 includes clear desk and clear screen as an explicit control, so any organisation certified against it — or answering its questionnaires — needs a written policy and evidence that staff follow it.
What a clean desk policy should cover
| Item | Rule | Notes |
|---|---|---|
| Papers and printouts | Filed or shredded at end of day; nothing sensitive left out | Collect printouts from the printer tray immediately |
| Screens and devices | Locked every time you step away; auto-lock after 5 minutes | Win+L on Windows, Ctrl+Cmd+Q on Mac |
| Removable media | USBs and external drives stored in a locked drawer | No unknown USBs plugged in — ever |
| Whiteboards and notes | Client names, credentials and contact details wiped or removed | Photos of whiteboards are a common leak |
| Visitor areas | Nothing visible from reception, meeting rooms or windows | Walk the route a visitor takes |
Keep the policy to one page. A twelve-page policy is a document nobody reads and nobody can be trained on.
How to train staff on it
1. Explain the why, with a real consequence
Staff follow rules they understand. Open with the failure mode: a competitor or scammer photographs a screen, or a payslip left on a desk becomes a privacy complaint to the OAIC. Human error drove 37% of Australian breaches in the first half of 2025 — a reminder that the small, everyday slip is where breaches actually start.
2. Rehearse the leaving-the-desk moment
The habit lives or dies in the two seconds when someone stands up. Run it as a drill: the phone rings, you stand — what do you do? Lock the screen, papers away, drawer closed. Repeat it until the sequence is automatic, the same way you rehearse verifying a payment request. A memo describing the moment does not train the moment.
3. Run the visitor test
Have a colleague walk the office as a visitor would — reception, corridors, meeting rooms — and photograph what is visible (with your approval and only internally). Count what a stranger could learn in ten seconds: client names on a whiteboard, an invoice on a desk, an unlocked laptop facing the door. Share the results with the team, without naming individuals. This makes the risk concrete in a way no policy statement does.
4. Fold it into recurring training
Clean desk is one behaviour among many. It works best as part of a monthly cadence rather than a once-a-year policy launch. Cyber Aware's training ships short modules you can assign on a schedule — pair a clean-desk module with phishing and password modules so the behaviours reinforce each other. An unlocked screen and a forwarded phishing attachment are the same failure type: information handed to someone who should not have it.
5. Spot-check and measure
Pick a simple measure — the percentage of desks passing a weekly five-minute walk — and track the trend, not the individuals. Coach failures privately. Publish the trend openly. What gets a number gets attention, and what gets a public shaming gets resentment instead of compliance.
6. Keep the evidence
Auditors, certifiers and insurers ask two things: is there a written policy, and can you show staff were trained on it. Keep the policy, the training completion records and the spot-check trend together. Cyber Aware's gap assessment shows where the human-risk gaps sit before an auditor finds them, and completion records per person can be exported as evidence.
Common mistakes
- Publishing a memo and calling it training. A rule nobody has rehearsed is a rule nobody applies under pressure.
- Clear desk without clear screen. The two go together; a tidy desk with an unlocked laptop still leaks everything.
- Shaming individuals publicly. Private coaching keeps reporting honest and people cooperative.
- Exempting remote and hybrid workers. Documents and screens at home carry the same duty of care — adapt the rules, do not drop them.
- One-off launch. Habits decay within weeks; the monthly cadence is what keeps them.
FAQ
Does a clean desk policy apply to remote workers? Yes. Sensitive papers and unlocked screens at home are exposed to household members, visitors and delivery people. Adapt the rules — lockable storage, automatic screen locks, shredding or secure return of papers — rather than exempting home workers.
How often should we train the clean desk policy? At onboarding for new starters, then as a short reinforcement module on a monthly cadence. A single annual briefing does not produce a daily habit.
Is locking the screen enough on its own? No. An unlocked policy also covers papers, printouts, USBs and what is visible from visitor areas. Screen locking is one control inside a wider policy.
How do we get senior staff to comply? Hold everyone to the same rule and start with the leadership team's own desks. Nothing kills a policy faster than staff seeing managers exempt from it.