AEGITz · Free Resource · Compliance Template

Written Information Security Program

Mapped to the nine elements of the FTC Safeguards Rule. Written matters: an undocumented set of good practices does not satisfy the rule, and in an inquiry the document is the first request.

This is a template, not legal advice. Confirm applicability and adequacy with your own counsel. A ten to fifteen page WISP that names the qualified individual, references your actual systems, and is signed and dated is what "good" looks like for a fifteen-person firm.

Firm:     Effective date:     Version:     Next review:  

1. Purpose and applicability

This program establishes the administrative, technical, and physical safeguards   maintains to protect the security, confidentiality, and integrity of customer information, as required by the FTC Safeguards Rule under the Gramm-Leach-Bliley Act. It applies to all employees, contractors, and service providers with access to customer information.

Consumer count:   consumers whose information the firm maintains. Count carefully: this includes prior year clients and the individuals inside business returns. Firms near 5,000 should count rather than estimate.

2. Qualified individual

The following individual is designated as responsible for overseeing, implementing, and enforcing this program:

Name     Title     Contact  

Where the firm uses an outside provider to support this function, the provider is  , and the firm retains accountability. Accountability cannot be outsourced.

3. Risk assessment

The firm conducts and documents a written risk assessment identifying reasonably foreseeable internal and external risks to customer information, evaluating the sufficiency of existing safeguards, and driving the controls in section 4.

ElementDetail
Date of most recent assessment 
Performed by 
FrequencyAnnually and after material change
Location of the written assessment 

4. Safeguards

4.1 Data inventory

The firm maintains an inventory of customer information and the systems that collect, store, transmit, and dispose of it. Location of the inventory:  

4.2 Access controls

Access is role-based and limited to what each role requires. Access is reviewed when roles change and terminated on departure. Review frequency:  

4.3 Multi-factor authentication

MFA is required for any individual accessing customer information on the firm's systems. This is not conditional. Covered systems:  

4.4 Encryption

Customer information is encrypted in transit and at rest, including on laptops and portable media. Client transmission occurs by secure portal / encrypted email.

4.5 Disposal

Customer information is securely disposed of within two years of the last date it was used, unless retention is otherwise required. Retention exceptions:  

4.6 Change management

Changes to systems handling customer information follow a documented process so that a configuration change does not silently remove a control. Process owner:  

4.7 Monitoring of authorized users

Activity of authorized users is logged and reviewed. Log retention:     Review cadence:  

5. Testing

The firm has adopted continuous monitoring / annual penetration testing plus semi-annual vulnerability assessment. Testing also occurs after any material change, including a new system or office.

TestFrequencyLast performedPerformed by
Vulnerability assessment   
Penetration test   
Restore test   

6. Personnel and training

Security awareness training is delivered at hire and at least annually, with attendance recorded. Firm email compromise is the leading cause of tax-related client fraud, so training emphasizes credential phishing and payment verification.

Training provider:     Records held at:  

7. Service provider oversight

Providers are selected based on their ability to safeguard customer information, required by contract to maintain appropriate safeguards, and periodically reassessed.

ProviderServiceSafeguards verifiedContract terms in placeNext review
     
     

8. Incident response plan

This plan covers the goals of response, internal processes, roles and responsibilities, external and internal communications, remediation, documentation, and post-incident evaluation of the program.

RolePersonContact
Incident lead  
Makes the notification determination  
Outside counsel  
Cyber insurance carrier  
IT or security provider  
FTC notification. A security event involving unencrypted customer information of 500 or more consumers must be reported to the FTC through its online form, generally as soon as possible and no later than 30 days after discovery. The clock runs from discovery, not from the end of your investigation. Arizona breach notification obligations apply alongside the federal requirement and the timelines are not identical.

9. Program evaluation and reporting

The qualified individual reports in writing to the board / a senior officer at least annually, covering the overall status of the program, compliance, and material matters including risk assessment results, testing results, security events, and recommended changes.

Last report delivered:     Next due:  

Adoption

This program is adopted by the firm and is effective as of the date below.

Name     Title     Signature     Date