The Written Information Security Program (WISP): What it Is and How to Build One

A written information security plan is the central requirement of the FTC Safeguards Rule. If you run a tax preparation firm, an accounting practice, or a non-bank financial institution, the federal government requires you to have this document. It outlines exactly how your business protects customer data from cyber threats. The written information security program (WISP) is the core deliverable that proves you are actively managing your cybersecurity risks.
Many business owners only hear about this requirement when their tax software vendor or the IRS tells them they need one. However, a WISP is not just a piece of paper you print and file away. It is a comprehensive information security program that dictates how you assess risk, train employees, and deploy technology to keep sensitive data safe. The program is built on a written risk assessment and covers required safeguards, testing, training, vendor oversight, and incident response.
The Gramm-Leach-Bliley Act (GLBA) is a 1999 federal law that requires financial institutions to explain how they share and protect their customers’ nonpublic personal information. Its data security piece is implemented for non-bank businesses by the FTC Safeguards Rule (16 CFR Part 314). The FTC amended this rule in 2021, and the key prescriptive provisions became mandatory on June 9, 2023. A breach notification requirement was added later.
Effective May 13, 2024, covered businesses must report to the FTC within 30 days of discovery any security events involving the unencrypted information of 500 or more consumers.
Who Must Comply with the Rule
The FTC Safeguards Rule requires non-bank financial institutions under FTC jurisdiction to develop, implement, and maintain a comprehensive WISP to protect customer information. The definition of a financial institution surprises many business owners. If your business is significantly engaged in providing financial products or services to consumers, you should assume you are covered until proven otherwise.
| Entity Type | Example |
|---|---|
| Auto finance | Auto dealers that arrange financing or leasing |
| Mortgage and lending | Mortgage brokers, non-bank lenders, payday and consumer lenders, finance companies |
| Tax and accounting | Tax preparation firms, accountants, CPA firms |
| Debt and payments | Debt collectors, check cashers, wire transferors |
| Investment and real estate | Investment advisers not required to register with the SEC, real estate settlement services |
| Education | Colleges and universities participating in federal student aid |
All of these organizations must implement a formal data security plan for small business compliance.
What a WISP Must Contain
Under Section 314.4 of the Safeguards Rule explained, your WISP must cover the nine required elements. These requirements dictate your administrative, technical, and physical safeguards.
- Designate a Qualified Individual: You must name a single person to implement and supervise the program.
- Conduct a Written Risk Assessment: You must base your entire program on a formal evaluation of your security risks.
- Implement Specific Safeguards: You must deploy access controls for customer data and maintain a hardware and data inventory. The amended rule specifically mandates encryption requirements for financial data both at rest and in transit. You also need multi-factor authentication (MFA) for any individual accessing any information system that holds customer information. Additionally, you must have secure development practices, secure disposal procedures for customer information no longer needed, change management, and monitoring of authorized user activity.
- Test Your Safeguards Regularly: You must use continuous monitoring or perform annual penetration testing alongside vulnerability assessments at least every six months.
- Deliver Employee Training: You must meet employee cybersecurity training requirements to ensure your staff understands security awareness.
- Oversee Service Providers: You must vet your vendors and bind them to security standards by contract.
- Keep the Program Current: You must update your WISP as your business changes.
- Create an Incident Response Plan: You must maintain a written data breach response plan to handle security events.
- Report to Leadership: The Qualified Individual must report in writing to your board or senior leadership at least annually.
Quick reference:
| # | Requirement | What It Covers |
|---|---|---|
| 1 | Designate a Qualified Individual | Name a single person to implement and supervise the program |
| 2 | Conduct a Written Risk Assessment | Base the program on a formal evaluation of your security risks |
| 3 | Implement Specific Safeguards | Access controls, hardware and data inventory, encryption at rest and in transit, MFA, secure development, secure disposal, change management, monitoring of authorized user activity |
| 4 | Test Your Safeguards Regularly | Continuous monitoring or annual penetration testing, plus vulnerability assessments at least every six months |
| 5 | Deliver Employee Training | Meet employee cybersecurity training requirements for security awareness |
| 6 | Oversee Service Providers | Vet vendors and bind them to security standards by contract |
| 7 | Keep the Program Current | Update your WISP as your business changes |
| 8 | Create an Incident Response Plan | Maintain a written data breach response plan |
| 9 | Report to Leadership | The Qualified Individual reports in writing to your board or senior leadership at least annually |
How to Actually Build Your Program
Building a WISP starts with understanding your current environment. You cannot protect what you do not know you have.
- Conduct a formal risk assessment for small businesses. This step helps you identify where your personally identifiable information protection efforts fall short. Document your hardware, your software, and the exact locations where customer data lives.
- Implement technical safeguards. Set up MFA and encryption. The rule requires MFA and encryption unless the Qualified Individual approves in writing a reasonably equivalent control.
- Establish physical safeguards. Lock cabinets for paper records, put secure document disposal procedures in place, and enforce clean desk policies.
- Establish administrative rules and document everything. Set remote access policies and vendor oversight procedures, and document every control clearly in your WISP.
The Danger of Free WISP Templates
Many tax professionals look for free templates to satisfy IRS WISP requirements. The IRS does provide guidance, such as Publication 5708, which offers a framework for creating a plan. However, downloading a template and putting your company name at the top is not FTC Safeguards Rule compliance.
The FTC requires you to actually operate the program you document. If your WISP says you require MFA and continuous monitoring, but you never actually deploy those tools, you are out of compliance. A template is only useful if it accurately reflects the real cybersecurity policy for small businesses that you enforce every day. The program itself is the point, not the paper it is printed on. You must actively manage your WISP requirements year after year.
The Role of the Qualified Individual
The FTC requires you to name a designated security officer, known as the Qualified Individual. This single named person is responsible for implementing and supervising the information security program.
The Qualified Individual can be an employee, or it can be a person at an affiliate or service provider. Many covered SMBs designate a role supported by their managed IT provider. While an MSP can implement the technical safeguards and testing, the business always retains legal responsibility for compliance.
Enforcement and Penalties
Unlike PCI DSS, the Safeguards Rule is enforced directly by the federal government. The FTC can investigate your business, bring enforcement actions, and impose consent orders that come with years of strict government oversight obligations. The FTC can also seek civil penalties for violations. Failing to maintain a compliant WISP puts your business at significant financial and legal risk.
See Where You Stand
Free 2-minute Safeguards Rule self-check: 8 plain-English questions, your risk level and the gaps to fix. No sign-up to see your result. free Safeguards Rule compliance self-assessment
Related Guides
- What Is the Gramm-Leach-Bliley Act (GLBA)? Plain English
- GLBA / FTC Safeguards Rule Requirements: The 9 Elements
- What Is the FTC Safeguards Rule? Who It Covers, What Changed
- GLBA Compliance: Who It Covers and What It Requires
Frequently Asked Questions
What is a written information security plan?
A written information security plan is a formal document that details how a business protects customer data. It outlines the administrative, technical, and physical safeguards used to prevent unauthorized access. The FTC requires this document as the foundation of your cybersecurity program.
Does the IRS require a written information security plan?
Yes, the IRS requires professional tax preparers to have a written information security plan. This aligns with the FTC Safeguards Rule, which mandates that non-bank financial institutions protect consumer data. Many tax professionals first hear about this requirement from their tax software vendor’s compliance expectations or directly from the IRS.
Why does a tax office need a written security plan?
Tax offices handle massive amounts of highly sensitive financial and personal data. Cybercriminals frequently target accounting and tax firms to steal this information for identity theft and tax fraud. A written security plan ensures the office has the proper controls in place to defend against these attacks.
How to prepare a WISP?
You prepare a WISP by first conducting a comprehensive risk assessment to identify vulnerabilities in your network and physical office. Next, you document the specific security controls you will use to mitigate those risks, such as encryption and multi-factor authentication. Finally, you must designate a qualified individual to manage the plan and keep it updated annually.
Does the IRS require a WISP?
Yes, the IRS requires tax preparation firms to maintain a WISP to comply with federal law. The IRS mandates that tax professionals protect taxpayer data and relies on the FTC Safeguards Rule framework to enforce this standard. Failing to maintain a program can expose your tax practice to FTC enforcement action and IRS penalties for noncompliance.
What is the penalty for not having a WISP?
The FTC enforces the Safeguards Rule and can launch investigations or bring enforcement actions against non-compliant businesses. Penalties can include consent orders that require years of strict government oversight. The FTC can also seek severe civil penalties for violations.
Get Help Building and Managing Your WISP
Writing a WISP is only the first step toward compliance. LeadingIT is a Chicagoland managed IT and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations and over 2,500 users from our offices in Woodstock and Manteno. LeadingIT implements and operates the technical safeguards the Rule requires (MFA, encryption, monitoring, testing, incident response) and can serve as or support the Qualified Individual role.
LeadingIT does not certify FTC compliance, because no such certification exists. Instead, we help you become and stay compliant. Learn more about LeadingIT’s FTC Safeguards compliance services, contact us to discuss your needs, or book a call directly.
