Purpose
The purpose of this policy is to establish the minimum requirements for maintaining clean desks and clear screens and to ensure that where there is any confidential, restricted, or sensitive information, it is locked away and is out of sight.
Scope
This policy applies to all employees, contractors, subcontractors, consultants, temporaries, guests, and any third party that uses eOne Solutions information assets or information resources and services.
Policy
Clear Desk Policy
- Hard copy documents containing any personal data or confidential, restricted, or sensitive information should only be stored safely. Examples are contracts with clients, contractors, employees and NDA.
- Prefer to use digital versions of documents instead of printed copies.
- Any confidential, restricted, or sensitive information must be removed from desks and locked in a drawer when a desk is left unoccupied at any time.
- Keys for the server room must not be left in or on an unattended desk. The keys’ owner is responsible for keeping them safe.
- No confidential information must be left in meeting rooms, either on the table, slides, or on whiteboards.
- Passwords must not be left on sticky notes posted on or under a computer or written down and left in an accessible location.
- Any information sent to printers should be retrieved as soon as practical.
Clear Screen Policy
- When leaving their desks for any period, staff must ensure that they lock their computer to prevent unauthorized access to information or systems.
- Lock your screen when you leave your computer unattended:
- For Windows devices: Press Ctrl, Alt, and Delete keys simultaneously and then ENTER or Press the Windows button on your keyboard and L simultaneously
- For macOS running macOS Mojave: go to the Apple menu and choose Lock Screen or press Command+Control+Q. This will lock your Mac and return you to the Login screen.
- For macOS running an earlier operating system: press the Control+Shift+Power button (or Control+Shift+Eject if your Mac has an optical drive). It will lock the screen.
- For Linux – Ctrl+Alt+L or Super+L (i.e., holding down the Windows key and pressing L) should work. Once your screen is locked, you will have to enter your password to log back in.
- Computer workstations must be logged off at the end of the working day to install security updates during the evening.
- Screensavers and computer timeouts must be password protected.
- All computer screensavers should be set for a maximum of fiftenn (15) minutes to lock, requiring a password to re-enter the computer.
- Keeping items 4 and 5 (above) of security configuration on the user workstation is the contractor and employees’ responsibility.
Disciplinary actions
Employees who violate this policy may face disciplinary consequences in proportion to their violation. Management will determine how severe an employee’s offense is and take the appropriate action.
Change, Review, and Update
This policy shall be reviewed once every year unless the owner considers an earlier review necessary to ensure that the policy remains current. Changes to this policy shall be exclusively performed by the Information Security Manager and approved by the IT Committee.
Responsibility
This is the responsibility of the Information Security Manager to maintain and make sure everyone is aware of this policy.
Revisions
- 19 September 2024
- This policy will be reviewed for continued completeness, relevance, and accuracy at yearly intervals or less.
Need to contact us?
If there are any questions regarding this Clear Desk and Screen Policy, you may contact us using the information below.
4170 41st Avenue South, Suite 101
Fargo, ND 58104
USA
+1 888-319-3663