Why it matters
Sensitive information left visible is a low-effort, high-frequency way for it to leak.
How a self-led small team implements it
A short written expectation plus screen-lock enforcement via MDM covers this practically.
What auditors expect to see
Clear desk policy, screen-lock configuration.
Track A.7.7 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS