Physical security is a critical and sometimes overlooked aspect of cyber security. Security should be looked at as a holistic effort to protect important assets – from employees and hardware to customer data and intellectual property. An important part of protecting these assets and bolstering both your physical and cyber security is through the implementation of a clean desk policy.
In addition to improved security, a clean desk policy is also a simple way to promote security awareness among your employees. Plus, organizations are increasingly including clean desk policy mandates into standard vendor contracts, and similar policies are a requirement of many security and privacy frameworks, including ISO27001 and 27002.
In a hurry? Just fill out this form, and we'll send you an email with our clean desk policy template.
A clean desk policy is simply a documented protocol that establishes requirements for how employees should handle company information and materials within the office. It can include requirements for computers, mobile devices, printed materials, and access cards, as well as for how workspaces should be maintained.
Document your clean desk policy. Include it in your employee handbook or information security policy.
Communicate the policy. Provide periodic reminders of what it is and where to find it (make it part of the culture).
Hold everyone accountable. Everyone from the CEO down to the newest hire should be required to adhere to the policy. Every employee handles information that could compromise the organization.
Provide alternatives. Give your employees secure places to keep things – locking drawers, file cabinets, lockers, etc. Without the right tools, you won’t be able to create a secure environment.
Assign responsibility for enforcement. Department managers should pass through the office near the end of each work day to ensure that workspaces are compliant with the policy.
Limit hard copies. Only print documents when absolutely necessary; your organization should develop a preference for electronic documents.
A clean desk policy is relatively easy to enforce, and has a place at any organization regardless of industry, so we encourage its widespread adoption. To help get you started, we’ve provided a proven template below.
[Company Name] stands committed to the development of secure policies and practices, and in doing so, has implemented this Clean Desk Policy to increase physical security at [Company Name] locations. This policy ensures that confidential information and sensitive materials are stored away and out of sight when they are not in use or when the workspace is vacant.
This policy sets forth the basic requirements for keeping a clean workspace, where sensitive and confidential information about [Company Name] employees, clients, vendors, and intellectual property is secured.
The policy shall apply to all [Company Name] employees, contractors, and affiliates.
It is the responsibility of each [DEPARTMENT MANAGER OR EQUIVALENT] to ensure enforcement with the policies above. Repeated or serious violations of the clean desk policy can result in disciplinary actions in accordance with [COMPANY NAME]’s Employee Handbook.
If you notice that any of your devices or documents have gone missing, or if you believe your workspace has been tampered with in any way, please notify [RELEVANT CONTACT] immediately.
Subscribe to Focal Point's Risk Rundown below - a once-a-month newsletter with templates, webinars, interesting white papers, and news you may have missed. Thousands of your colleagues and competitors have signed up! You can unsubscribe at any time.