Assurance/Adherence - Internal and external auditors should include a review of the information classification status within the organization as a component of their regular audit process. This should include an evaluation of the level of compliance with the classification policy and procedures to ensure that all parts of the organization are properly adhering to the process. Part of this review may detect cases where information is over-classified - a situation that often detracts from the purposes of classification when non-compliance is observed. Information security staff personnel should regularly visit workstations and other areas where classified materials may be left unprotected and ensure that appropriate reports are made to supervisors and managers. Ideally, employee performance evaluations should include records of mishandling classified information in order to bring to their attention the importance of this process. One of the requirements an organization may enforce is the Clean Desk/Clear Screen policy where an unattended desk or workstation should never have sensitive information sitting in open view.