The goal of the policy
This policy aims to regulate clean desk practices to provide a secure work environment that protects information from internal and external threats, ensuring the safeguarding of sensitive information against unauthorized access, loss, or destruction, in implementation of the National Cybersecurity Authority (NCA) controls and in accordance with the ISO 27001 international standard for information security.
Policy scope
This policy applies to all IT and technical projects, all offices, office equipment, and meeting rooms, including university personnel, temporary staffing agency employees, vendors, partners, contractor employees, and functional units regardless of geographical location. The Cybersecurity Department is responsible for resolving any issues arising from the implementation of this policy.
Policy elements
- All desktop and laptop computers must be secured with a password.
- Any sensitive or confidential data/files must be removed from the desktop.
- The device screen must be locked before leaving the office.
- It is strictly forbidden to leave any sensitive information or unlocked devices in shared workspaces or in front of visitors.
- Passwords written on paper or shared must not be used.
- Systems and applications must be logged out of when not in use.
- Locks must be used for drawers and cabinets designated for storing sensitive documents and devices.
- Paper documents must not be left on desks or in common areas.
- Make sure to clean and remove any information or documents after using meeting rooms or shared areas.