Physical Security & Clean Desk

MODULE 07 / OPERATIONAL8 min / Includes knowledge checks and quiz

Physical Security & Clean Desk

Cybersecurity is not only digital. Learn the physical security practices, from tailgating prevention to clean desk policies to secure disposal, that protect your organization.

A modern office entrance with a keycard badge reader on the wall next to a glass door, an employee tapping their access badge

What You Will Learn

Cybersecurity is not only digital. Physical access to your office, devices, and documents can lead to data breaches just as easily as a phishing email. This module covers the physical security practices that protect your organization.

  • Tailgating prevention: controlling who enters your space
  • Device security: locking screens, encrypting drives, securing laptops
  • Clean desk policy: keeping sensitive documents out of sight
  • Screen privacy: preventing visual data exposure in public spaces
  • Secure disposal: properly destroying documents and devices

Why Physical Security Matters

A locked door is a security control. A shredded document is a security control. A laptop with full-disk encryption is a security control. Physical security is required by ISO 27001 and NIST SP 800-50, and it is often the weakest link in small organizations that focus exclusively on digital threats.

Consider this: if someone walked into your office after hours, what could they access? Printed patient records on a desk? A logged-in computer? A server closet with no lock? Physical security closes these gaps.

Quick Check

You are entering your office building and someone you do not recognize is right behind you. They say they are visiting a colleague. What should you do?

A) Hold the door. It is the polite thing to do.
B) Direct them to the front desk to check in, then proceed.
C) Let them in but watch where they go.
D) Ask them their name and let them in.

Tailgating and Access Control

Tailgating is when an unauthorized person follows someone through a secure door. It is the most common physical security breach. It works because challenging strangers feels socially awkward. But in a regulated environment, it is a serious risk.

Access Control Best Practices

  • Challenge strangers. Asking to see a badge is professional, not rude.
  • Do not hold doors for people you do not recognize. Direct them to the front desk to check in.
  • Keep doors locked. Exterior doors, server closets, and file rooms should be locked at all times.
  • Report suspicious visitors. If someone is wandering your office without a badge or escort, notify management.
  • Escort visitors. Any visitor including vendors, clients, and auditors should be escorted in restricted areas.

Device Security

Screen Locking

Set your computer to lock automatically after 5-10 minutes of inactivity. Manually lock every time you step away. An unlocked screen gives anyone full access to your accounts and files.

Full-Disk Encryption

If your laptop is lost or stolen, full-disk encryption ensures the data on it is unreadable without your password. Without encryption, a thief can remove the hard drive and read everything. STM can help verify encryption is enabled on all your devices.

Laptop and Phone Security

  • Never leave laptops visible in a parked car. Put them in the trunk before you arrive.
  • Use a laptop lock in public spaces or shared offices.
  • Enable remote wipe on phones and laptops so you can erase data if a device is lost.
  • Do not leave devices unattended in coffee shops, airports, or conference rooms.

Quick Check

You need to dispose of old patient intake forms. What is the correct method?

A) Throw them in the recycling bin
B) Use a strip-cut shredder
C) Use a cross-cut shredder or certified shredding service
D) Tear them in half and throw away

Clean Desk Policy

A clean desk policy means no sensitive documents are left out when you are not at your desk. This is a required control for ISO 27001 and is a simple, effective practice:

  • Lock documents away at the end of the day in a locked drawer, cabinet, or office
  • Do not leave printed records on the printer. Pick up print jobs immediately.
  • Shred sensitive documents. Never toss them in the regular trash.
  • Clear your desk of sticky notes with passwords, client names, or account numbers
  • Whiteboards with sensitive information should be erased when not in use

Secure Disposal

Disposal Rules

  • Paper documents: Shred with a cross-cut shredder. Strip-cut shredders are not sufficient because the strips can be reassembled.
  • Old hard drives: Use a certified e-waste recycler that provides a certificate of destruction. STM can help arrange secure disposal.
  • Old phones and tablets: Factory reset is NOT enough because data can still be recovered. Use a certified recycler or data destruction service.
  • USB drives: Physically destroy them or use secure wipe software before disposal.
  • Printer hard drives: Many office printers store copies of printed documents. Clear the printer memory before disposing of it.

How This Looks in Your Industry

Healthcare Practices

Printed patient records left on desks, counters, or printers are HIPAA violations. A clean desk policy is one of the simplest HIPAA safeguards. Lock patient files away when not in use, and never leave charts where visitors can see them.

Legal Firms

Case files left on desks can expose privileged information to anyone walking through the office. Lock case files in cabinets or offices at the end of each day. Shred all confidential documents with a cross-cut shredder.

Nonprofits

Donor lists, financial reports, and grant documents left on desks can expose sensitive information to volunteers and visitors. A clean desk policy protects donor trust and grant compliance.

Daycares and Schools

Student records, parent contact information, and incident reports must be secured. Staff photos of children on personal phones create COPPA and state privacy risks. Lock all student records away when not in use.

Key Takeaways

  • Physical security is a required control. ISO 27001 and NIST SP 800-50 both mandate it.
  • Challenge strangers in your office. Asking for a badge is professional, not rude.
  • Lock your screen every time you step away. Set auto-lock for 5-10 minutes.
  • Full-disk encryption ensures a lost or stolen laptop’s data is unreadable without the password.
  • Shred sensitive documents with a cross-cut shredder. Strip-cut is not sufficient.

Module Quiz

Select an answer for each question to reveal the correct response and explanation.

1. You are entering your office building and someone you do not recognize is right behind you. They say they are visiting a colleague. What should you do?

A) Hold the door. It is the polite thing to do.
B) Direct them to the front desk to check in, then proceed.
C) Let them in but watch where they go.
D) Ask them their name and let them in.

2. You need to dispose of old patient intake forms. What is the correct method?

A) Throw them in the recycling bin
B) Use a strip-cut shredder
C) Use a cross-cut shredder or certified shredding service
D) Tear them in half and throw away

3. Your organization is replacing old laptops. What should you do with the old devices?

A) Donate them to a local charity
B) Throw them in the trash
C) Use a certified e-waste recycler that provides a certificate of destruction
D) Factory reset and sell them online

4. Why is full-disk encryption important for laptops?

A) It makes the laptop run faster
B) If the laptop is lost or stolen, the data is unreadable without the password
C) It prevents viruses
D) It is required by all email providers

5. What is a clean desk policy and why does it matter?

A) A policy to keep desks tidy for aesthetic reasons
B) A policy requiring no sensitive documents be left out when you are not at your desk, required by ISO 27001
C) A policy that requires desks to be cleaned daily by janitorial staff
D) A policy that prohibits personal items on desks

Module 07 of 10 – Cybersecurity Essentials Training

Previous ModuleBack to ResourcesNext Module