Skip to main content

Personal tools

Translate

PE27 Clear Desk and Screen Procedure

Procedural Directive PE27 Clear Desk and Screen Procedure

Purpose

This administrative procedure establishes the requirements to reduce the risks of unauthorized access, loss, and damage to APS confidential or sensitive information on desks, screens, and in other accessible locations during and outside normal working hours.

Scope

This administrative procedure applies to all APS employees, staff, students, temporary staff, interns, third parties, and subcontractors affiliated with third parties who use or have access to APS confidential or sensitive information in APS offices, schools, off-site, at home, at a client's premises, or at any other location, regardless of information form or format (hardcopy, digital, or spoken information).

It is the responsibility of APS personnel to read and understand this procedure and to conduct their activities in accordance with its terms.

Guidelines and Requirements

  • All APS workspaces must be free of confidential or sensitive information when not in use or when the user is away from it.
  • Confidential or sensitive information (electronic or hard copy) must be locked securely when the user is away from the workspace or when the information is not required. Physical documents must be filed in a secure location (e.g., locked file cabinets, drawers, physical areas, or in a safe). Electronic documents must be stored on encrypted computers/laptops with strong passwords (See PG 25 Password Management Procedural Directive).
  • Laptops that process or store confidential or sensitive information and are not encrypted must be either locked with a locking cable or locked away in a drawer or cabinet when the work area is unattended or at the end of the workday.
  • Keys used to access devices or sensitive or confidential information must be kept secure. Access to these keys must be limited to certain personnel, and a record must be kept of who has access to them.
  • Workstations, laptops, and mobile devices must be locked (using the Ctrl+Alt+Delete function) when the workspace is unoccupied, even for a few moments. All computers and systems must be configured with a timeout or automatic logout feature.
  • When attending to visitors or others who may come into your workspace for a legitimate interaction, but are not authorized and do not have a need to know, you must exit screens with sensitive or confidential information and maintain a clear screen.
  • All APS personnel must log off from computers, laptops, applications, or network services at the end of the day or when they are no longer needed.
  • The following information must not be written down or posted in an accessible location:
    • Passwords: this includes but is not limited to work-related passwords and personal passwords
    • Personal identifiable information (PII): Information that can be used to identify an individual (e.g., address, date of birth, social security number)
    • Personal health information: Information relating to the health of an individual (e.g., medical records)
    • Student information
    • Employee information: Information relating to employees that is sensitive and confidential (e.g., address, date of birth, salary)
  • Whiteboards, screens, and other types of displays must be cleansed of sensitive or confidential information and not used if visual or physical access to them cannot be restricted to those who need to know.
  • Sensitive or critical information on whiteboards and other types of display must be clear when no longer required.
  • When the workstation is unattended, personal items such as phones, wallets, and keys should be removed or placed in a locked drawer or file cabinet.
  • Printers that require users to sign in before printing should be used to help ensure only the person who originally printed the pages is allowed to collect them.
  • Any printed confidential or sensitive information must not be left unattended around printers or fax machines. It must be collected immediately.
  • All printers and fax machines with papers that have not been retrieved by the end of the day must be disposed of in the provided containers (e.g., shredded, burned, etc.).
  • Confidential or sensitive information, documents, and removable media must be disposed of in designated, locked shred containers.
  • Mass storage devices (e.g., CD-ROM, DVD, or USB drives) must be treated and marked as sensitive and properly secured. Password protection should be used whenever possible.
  • Any loss of a device, confidential or sensitive information, or violations of this procedural directive must be immediately reported to the Technology Service Desk.
  • Confidential or sensitive information must not be shared with third parties unless prior authorization and a need to know are granted. It can also not be disclosed or discussed with unauthorized people or at public events.
  • Random spot checks must be conducted periodically by the Information Security team to ensure that employees are in compliance with the clear desk and screen guidelines.

Compliance

Any APS employee, staff member, or other individual bound by APS administrative procedure who is found in violation of this administrative procedure may be subject to disciplinary action, up to and including termination of employment. Any third-party partner company or contractor found in violation may face legal consequences and potential termination of the contract.

References

Administrative Position:

  • Deputy Superintendent of Operations

Department Director:

  • Chief information Security Officer

Procedural Directive Cross Ref.:

Support Document:

NSBA/NEPN Classification: EGD

Adopted: October 6, 2025