A.7.7 Physical
Clear desk and clear screen
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (12)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-11mostlyaligns with — Both controls require endpoint devices to be locked or session-protected when unattended, using authentication mechanisms to prevent unauthorized access.
- MP-4mostlyaligns with — Both controls mandate secure storage of physical and removable media containing sensitive information when not in active use.
- MP-6mostlyaligns with — The ISO requirement for secure disposal of sensitive documents and media directly supports NIST's media sanitization objective to prevent unauthorized disclosure.
- AC-7partialaligns with — The ISO guidance's automatic logout and timeout features align with NIST's requirement to limit unsuccessful logon attempts and protect against unauthorized session continuation.
- PE-18partialaligns with — The ISO guidance on clearing whiteboards and displays in shared or public spaces aligns with NIST's requirement to position system components to reduce unauthorized viewing.
- PE-5partialaligns with — Both controls address controlling access to output devices such as printers to ensure only authorized individuals can retrieve sensitive printed material.
Aligned NIST CSF 2.0 outcomes (11)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-05mostlyaligns with — The ISO control enforces policy-driven access restrictions by requiring unattended devices to be locked and sensitive materials to be secured, directly supporting the CSF outcome of managing and enforcing access permissions and authorizations.
- PR.AA-06mostlyaligns with — By mandating that physical workspaces and endpoint devices be secured when unattended, the control fulfills the CSF requirement to manage, monitor, and enforce physical access commensurate with risk.
- GV.PO-01partialaligns with — Establishing and communicating a topic-specific clear-desk and clear-screen policy directly supports the CSF outcome of creating policy for managing cybersecurity risks based on organizational context and priorities.
- PR.DS-01partialaligns with — Requiring sensitive information on paper or removable media to be locked away or securely disposed protects the confidentiality and integrity of data-at-rest in physical form.
- PR.PS-01partialaligns with — The control contributes to configuration management by requiring automatic screen-lock timeouts and secure device configurations to prevent unauthorized access when systems are left unattended.
Related OWASP ASVS 5.0 requirements (2)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (4)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialprevents — Requiring sensitive documents and screens to be locked or cleared when unattended directly reduces the chance that an unauthorized person can read or copy confidential data left in the open.
- CWE-284partialmitigates — Enforcing physical and session locks on unattended devices and storage prevents unauthorized actors from gaining access to resources that should be restricted.
- CWE-359partialmitigates — Clear-desk and clear-screen rules reduce the likelihood that private personal information remains visible or accessible to unauthorized viewers in shared workspaces.
- CWE-552partialmitigates — Mandating that sensitive files and removable media be stored securely or disposed of properly limits the exposure of resources that would otherwise be accessible outside their intended sphere.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005partialmitigates — Locking away or removing sensitive documents and media when the workspace is unattended directly reduces the opportunity for an adversary to collect files and data from the local system.
- T1025partialmitigates — Requiring immediate retrieval of printouts and secure storage of removable media limits an adversary’s ability to obtain data from physical media left in the environment.
- T1552partialmitigates — Storing credentials or sensitive information on paper or removable media in locked cabinets prevents an attacker from locating unsecured credentials in the physical workspace.
- T1078nonemitigates — Enforcing screen locks and automatic session timeouts on unattended devices reduces the chance that an adversary can use an already-authenticated session via a valid account.
- T1555nonemitigates — Locking away or promptly securing physical media and documents containing passwords or tokens prevents an attacker from harvesting credentials stored in the clear on the local system.
Prevented OWASP Web Top 10 (2025) risks (2)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialprevents — Enforcing automatic screen locks and session timeouts on unattended endpoints reduces the window during which an attacker with physical access can exploit default or misconfigured authentication settings.
- A07nonemitigates — Requiring user authentication to unlock screens and printers limits the ability of unauthorized individuals to bypass or abuse weak or absent authentication mechanisms on shared devices.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.