Firm Information
Basic details about your tax or accounting practice. This information will appear on the cover page of your WISP.
โน๏ธ Legal Requirement: Under the Gramm-Leach-Bliley Act (GLBA) and the FTC Safeguards Rule, all tax professionals are considered financial institutions and must maintain a written information security plan. See IRS Pub. 5708 โ
๐ข Practice Details
Click to upload or drag & drop your logo
PNG, JPG, SVG, or GIF ยท Recommended max width 400px
6-digit number assigned by the IRS
WISPs must be reviewed at least annually
๐ Types of Client Information Handled
Check all types of Personally Identifiable Information (PII) your practice handles:
Responsible Officials
Designate the individuals responsible for your information security program. The FTC Safeguards Rule requires you to name a qualified individual to coordinate your WISP.
๐ Data Security Coordinator (DSC)
The DSC is responsible for implementing, supervising, and maintaining the WISP โ including daily operations, employee training, vendor oversight, and incident response.
๐ข Public Information Officer (PIO)
The PIO is the single spokesperson for all outward communications related to any data breach โ client notifications, media, law enforcement statements. In a sole practice, this may be the same person as the DSC.
๐ฅ๏ธ IT Support / Service Provider
Risk Assessment
Identify and document internal and external risks to the security of client data. The FTC requires each firm to assess risks and evaluate existing safeguards.
โ ๏ธ Internal Risks
Check all internal risks that apply to your practice:
๐ External Risks
๐ Risk Monitoring Procedures
Hardware Inventory
Catalog all devices used in your practice that come into contact with client data. This is required under the FTC Safeguards Rule and IRS guidance.
๐ Include all computers, laptops, tablets, phones, printers, servers, routers, modems, USB drives, and any device that stores, processes, or transmits client PII.
๐ป Device Inventory
| Device Description | Physical Location | Principal User | Types of PII Stored/Processed | In-Service Date | |
|---|---|---|---|---|---|
โ๏ธ Cloud & Software Services Containing PII
Security Policies & Safeguards
Select the security policies your firm implements. These form the core of your WISP and demonstrate compliance with the FTC Safeguards Rule.
๐ Network & Access Control
๐ก Wi-Fi & Remote Access
๐ Data Handling & Transmission
๐ฅ Employee Training & Personnel
๐ค Third-Party Service Providers
๐
Record Retention Policy
IRS generally recommends 3โ7 years depending on record type
Security Breach Response Plan
Document your procedures for responding to a data breach. The FTC requires firms to report security events affecting 500 or more people within 30 days of discovery.
โ ๏ธ FTC Reporting Requirement: Security events affecting 500 or more customers must be reported to the FTC within 30 days of discovery via the FTC Safeguards Rule Security Event Reporting Form.
๐จ Breach Detection & Internal Notification
๐ External Notifications Required
Select all agencies and parties your firm will notify in the event of a data breach:
๐ก๏ธ Insurance & Legal
Authorized PII Access List
Maintain a record of all individuals โ employees, contractors, and vendors โ authorized to access client PII. This supports compliance and provides a chain of custody in the event of an investigation.
๐ชช Authorized Personnel
| Full Name | Role / Title | Job Duties | Access Level | Date Access Granted | Date Terminated | |
|---|---|---|---|---|---|---|
Include contractors (IT support, cleaning service, copier repair) who may have physical or electronic access to areas containing PII.
โ๏ธ Signatories
The WISP must be signed by the principal operating officer or owner and the Data Security Coordinator.
Your WISP Document
Review your completed Written Information Security Plan below. Click Print / Save as PDF to generate your official document.