Mapped to the nine elements of the FTC Safeguards Rule. Written matters: an undocumented set of good practices does not satisfy the rule, and in an inquiry the document is the first request.
Firm: Effective date: Version: Next review:
This program establishes the administrative, technical, and physical safeguards maintains to protect the security, confidentiality, and integrity of customer information, as required by the FTC Safeguards Rule under the Gramm-Leach-Bliley Act. It applies to all employees, contractors, and service providers with access to customer information.
Consumer count: consumers whose information the firm maintains. Count carefully: this includes prior year clients and the individuals inside business returns. Firms near 5,000 should count rather than estimate.
The following individual is designated as responsible for overseeing, implementing, and enforcing this program:
Name Title Contact
Where the firm uses an outside provider to support this function, the provider is , and the firm retains accountability. Accountability cannot be outsourced.
The firm conducts and documents a written risk assessment identifying reasonably foreseeable internal and external risks to customer information, evaluating the sufficiency of existing safeguards, and driving the controls in section 4.
| Element | Detail |
|---|---|
| Date of most recent assessment | |
| Performed by | |
| Frequency | Annually and after material change |
| Location of the written assessment |
The firm maintains an inventory of customer information and the systems that collect, store, transmit, and dispose of it. Location of the inventory:
Access is role-based and limited to what each role requires. Access is reviewed when roles change and terminated on departure. Review frequency:
MFA is required for any individual accessing customer information on the firm's systems. This is not conditional. Covered systems:
Customer information is encrypted in transit and at rest, including on laptops and portable media. Client transmission occurs by secure portal / encrypted email.
Customer information is securely disposed of within two years of the last date it was used, unless retention is otherwise required. Retention exceptions:
Changes to systems handling customer information follow a documented process so that a configuration change does not silently remove a control. Process owner:
Activity of authorized users is logged and reviewed. Log retention: Review cadence:
The firm has adopted continuous monitoring / annual penetration testing plus semi-annual vulnerability assessment. Testing also occurs after any material change, including a new system or office.
| Test | Frequency | Last performed | Performed by |
|---|---|---|---|
| Vulnerability assessment | |||
| Penetration test | |||
| Restore test |
Security awareness training is delivered at hire and at least annually, with attendance recorded. Firm email compromise is the leading cause of tax-related client fraud, so training emphasizes credential phishing and payment verification.
Training provider: Records held at:
Providers are selected based on their ability to safeguard customer information, required by contract to maintain appropriate safeguards, and periodically reassessed.
| Provider | Service | Safeguards verified | Contract terms in place | Next review |
|---|---|---|---|---|
This plan covers the goals of response, internal processes, roles and responsibilities, external and internal communications, remediation, documentation, and post-incident evaluation of the program.
| Role | Person | Contact |
|---|---|---|
| Incident lead | ||
| Makes the notification determination | ||
| Outside counsel | ||
| Cyber insurance carrier | ||
| IT or security provider |
The qualified individual reports in writing to the board / a senior officer at least annually, covering the overall status of the program, compliance, and material matters including risk assessment results, testing results, security events, and recommended changes.
Last report delivered: Next due:
This program is adopted by the firm and is effective as of the date below.
Name Title Signature Date