
A.11.2.9: Clear Desk and Clear Screen Policy
Adopt a clear desk policy for papers and removable storage media and a clear screen policy for information processing facilities.

A.11.2.8: Unattended User Equipment
Develop and implement procedures to protect unattended user equipment.

—A.7.2.1: Management Responsibilities
Require management to ensure that employees and contractors apply information security in accordance with established policies and procedures.

—A.7.1.2: Terms and Conditions of Employment
Ensure that employees, contractors, and third-party users agree to and sign the terms and conditions of their employment contract, which states their and the organization’s responsibilities for information security.

Contact with Special Interest Groups
Establish connections with special interest groups or other specialist security forums and professional associations.


Segregation of Duties
Reduce the risk of accidental or deliberate misuse of information system by segregating duties.

Information Security Roles and Responsibilities
Ensure that policies for information security are reviewed at planned intervals or when significant changes occur.

Policy Review for Information Security
Ensure that policies for information security are reviewed at planned intervals or when significant changes occur.