N.3.05 Regulations for leaving confidential information on desk and screen
Control Overview
This control mandates the formulation, communication, and enforcement of "Clear Desk" and "Clear Screen" policies across all environments where company data is processed. To prevent unauthorized individuals from viewing or misusing sensitive information at unattended workstations, the organization must ensure that physical documents and storage media are locked away when not in use. Additionally, active computer screens must be locked manually upon leaving a workstation, backed by automated session-timeout locks after a defined period of inactivity.
Applicability Note: This control is fully applicable to the anDREa platform and is primarily enforced through endpoint configuration profiles applied to our fully remote workforce.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement bridges physical user behavior with centralized, automated endpoint governance within our ISO/IEC 27001-based ISMS.
Because anDREa operates under a fully remote model, traditional office walkthrough audits are replaced by centralized technical constraints managed via Mobile Device Management (MDM). Our Remote Working Policy formally mandates clear-desk and clear-screen behaviors for home and remote offices. At the technical layer, company-managed devices are provisioned with automated inactivity screen-locks by default. While operational flexibility is permitted for long-running scripts or data processing tasks, access to the underlying platform remains continuously governed by persistent session controls and re-authentication parameters.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.07.07 - Clear desk and clear screen | Mandates that clear desk rules for papers and removable storage media, and clear screen rules for information processing facilities, are defined and implemented. |
| ISO/IEC 27001 | A.06.07 - Remote working | Extends the clear desk and clear screen behavioral obligations to external and home working environments. |
| Core Operational Policy | A.06.07 - Remote working | The authoritative text defining physical storage requirements for sensitive items and mandatory workstation-locking rules. |
| Technical Enforcement | MDM Configuration Baselines | Centralized system policies (Google) that enforce automated screen lockouts after a fixed duration of user inactivity. (A.08.01 - User end point devices) |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. The core combination of policy mandates and automated MDM inactivity locks meets the baseline standard.
- Continuous Improvement (NIS 2 Alignment): To maximize audit resilience against upcoming requirements, formally define a strict maximum allowed idle-lock timeout baseline (e.g., maximum 10–15 minutes) within the policy text. Furthermore, explicitly document the exception-handling workflow for long-running engineering tasks—such as using dedicated session-only exclusions or demanding step-up conditional access—to ensure flexibility does not introduce unmonitored risk.