- Clean Desk Policy
- A workplace rule requiring employees to secure or remove sensitive materials from their workstation whenever they are away from their desk.
- Clear Screen Policy
- A companion rule requiring employees to lock or log off their computer screen when leaving their workstation, preventing unauthorized viewing of on-screen data.
- Sensitive Information
- Any data β paper or digital β that could cause harm if disclosed to unauthorized parties, including personally identifiable information, financial records, and trade secrets.
- Removable Media
- Portable storage devices such as USB drives, external hard drives, SD cards, and optical discs that can carry data off-premises.
- ISO 27001
- An international standard for information security management systems that explicitly references clean desk and clear screen controls as physical security measures.
- SOC 2
- An auditing framework for service organizations that evaluates security, availability, and confidentiality controls β physical workstation security is often reviewed.
- Need-to-Know Principle
- The practice of restricting access to confidential information only to individuals whose role requires it.
- Tailgating
- A physical security breach where an unauthorized person enters a secured area by following an authorized employee through a controlled door.
- Data Classification
- A system that labels information by sensitivity level β such as public, internal, confidential, and restricted β to guide handling and storage requirements.
- Secure Disposal
- The destruction of physical documents or digital media in a way that makes recovery impossible, typically through cross-cut shredding or certified media wiping.