Clean Desk Basics
The password on your desk is a password anyone can read.
What Is Clean Desk Basics?
A password written down beside a keyboard needs no phishing and no malware. Anyone allowed into the building can read it and sign in as you. In this exercise you leave your desk for ten minutes with the screen unlocked and your notes where they are, then find out the next morning what a passer-by did with them. You audit every note on that desk, destroy the ones that hand out access, rotate what was read, and lock the screen before you leave again.
What You'll Learn in Clean Desk Basics
- Recognize that a written password, door code or client account number on an open desk is readable by everyone who is allowed into the building
- Judge each item on a desk by what it would give a stranger, rather than treating a clean desk policy as a tidiness rule
- Destroy the notes that carry access and leave the ones that carry nothing, so the rule is one people actually follow
- Lock the workstation every time you leave it, however short the trip and however familiar the floor
- Treat anything that has been readable as compromised: rotate the password, change the shared code, and tell whoever owns the data
Clean Desk Basics — Training Steps
-
A call on the calendar
Tuesday, 16:20. You are at your desk on the second floor. Devan in Ardwell IT has a short call booked to check your access to the Latchford client portal before tomorrow's review. A blank sticky pad sits by your keyboard, where it always does.
-
Open the meeting app
The call is a video meeting. You open it on your monitor.
-
Join the review
Devan is already waiting.
-
Devan reads out the password
Devan confirms your Latchford portal access is live and reads the password back to you so you can check it against your password manager.
-
Jot it down
You do what you always do on a call: you write it on the pad by your keyboard so you have it to hand.
-
Was that needed?
Before Devan wraps up, think about the note you just wrote.
-
The call wraps up
Devan signs off. It is nearly the end of the day. You head to the Birch room to set up for tomorrow. The screen stays unlocked, and the note stays by the keyboard.
-
A call from Security Operations
Wednesday, 08:05. You are still holding your coat when the phone goes.
-
The account activity
Rhona's email lands while you are still standing up.
-
Open the portal
You would rather not look. You look.
Security Framework Coverage
CWE
- CWE-522 Insufficiently Protected Credentials
CIS Controls
- CIS 14.4 Train Workforce on Data Handling Best Practices
- CIS 14.5 Train Workforce Members on Causes of Unintentional Data Exposure
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind