A.7.7 Physical
Clear desk and clear screen
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (21)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-11mostlyaligns with — Both controls require endpoint devices to be locked or session-protected when unattended, using authentication mechanisms to prevent unauthorized access.
- MP-4mostlyaligns with — Both controls mandate secure storage of physical and removable media containing sensitive information when not in active use.
- MP-6mostlyaligns with — The ISO requirement for secure disposal of sensitive documents and media directly supports NIST's media sanitization objective to prevent unauthorized disclosure.
- AC-7partialaligns with — The ISO guidance's automatic logout and timeout features align with NIST's requirement to limit unsuccessful logon attempts and protect against unauthorized session continuation.
- PE-18partialaligns with — The ISO guidance on clearing whiteboards and displays in shared or public spaces aligns with NIST's requirement to position system components to reduce unauthorized viewing.
- PE-5partialaligns with — Both controls address controlling access to output devices such as printers to ensure only authorized individuals can retrieve sensitive printed material.
- AC-11covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- AC-7covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- MP-4covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- MP-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-18covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PE-5covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (19)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-05mostlyaligns with — The ISO control enforces policy-driven access restrictions by requiring unattended devices to be locked and sensitive materials to be secured, directly supporting the CSF outcome of managing and enforcing access permissions and authorizations.
- PR.AA-06mostlyaligns with — By mandating that physical workspaces and endpoint devices be secured when unattended, the control fulfills the CSF requirement to manage, monitor, and enforce physical access commensurate with risk.
- GV.PO-01partialaligns with — Establishing and communicating a topic-specific clear-desk and clear-screen policy directly supports the CSF outcome of creating policy for managing cybersecurity risks based on organizational context and priorities.
- PR.DS-01partialaligns with — Requiring sensitive information on paper or removable media to be locked away or securely disposed protects the confidentiality and integrity of data-at-rest in physical form.
- PR.PS-01partialaligns with — The control contributes to configuration management by requiring automatic screen-lock timeouts and secure device configurations to prevent unauthorized access when systems are left unattended.
- GV.PO-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-06implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.DS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (2)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200prevents — Requiring sensitive documents and screens to be locked or cleared when unattended directly reduces the chance that an unauthorized person can read or copy confidential data left in the open.
- CWE-284mitigates — Enforcing physical and session locks on unattended devices and storage prevents unauthorized actors from gaining access to resources that should be restricted.
- CWE-359mitigates — Clear-desk and clear-screen rules reduce the likelihood that private personal information remains visible or accessible to unauthorized viewers in shared workspaces.
- CWE-552mitigates — Mandating that sensitive files and removable media be stored securely or disposed of properly limits the exposure of resources that would otherwise be accessible outside their intended sphere.
Mitigated MITRE ATT&CK techniques (36)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005prevents — A.7.7's policy, locking, screen-locking, secure storage and final-sweep rules stop an adversary from easily reaching unattended sensitive files on paper, removable media, unlocked endpoints or visible screens, which is a genuine but minority slice of the broad local-system search technique that also covers running processes, VM files, configuration stores, CLI on network devices and locked-but-still-present data.
- T1052prevents — A.7.7's policy, locking, secure storage, and disposal rules for removable media and sensitive data directly stop much of the user-introduced physical-medium exfiltration path described in T1052, but leave open vectors such as deliberate insider use of authorized devices or media introduced without violating the clear-desk rules.
- T1052.001prevents — A.7.7's policy, locking, timeout, and secure-storage rules for removable media and unattended devices stop or deter the casual insertion of an unauthorized USB device that would otherwise serve as the exfiltration vector, but do not block a determined insider who deliberately copies data to an allowed/authorized USB device.
- T1552prevents — A.7.7's policy, locking, screen-locking, secure storage and disposal rules directly stop many classes of unsecured credentials (paper notes, unlocked endpoint files, printouts, whiteboards) from being left accessible, but do not reach OS/application credential stores, registry entries, private-key files or shell history on already-compromised systems.
- T1552.001prevents — A.7.7's policy, locking, secure storage, and disposal rules reduce the presence of credential-containing files on accessible desks/shares (especially user-created or printed ones), but do not stop configuration files, source code, container logs, backups, or GPP-stored credentials.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.