WRITTEN INFORMATION SECURITY PLAN
CONFIDENTIAL — FIRM INTERNAL USE

Section 3. Access Controls (including Multi-Factor Authentication)

The Firm shall implement and periodically review access controls — including technical and, as appropriate, physical controls — designed to (i) authenticate and permit access only to Authorized Users, and (ii) limit each Authorized User’s access to only the Customer Information required to perform that user’s duties.

Multi-factor authentication. The Firm shall implement multi-factor authentication for any individual accessing any Information System, unless the Qualified Individual has approved, in writing, the use of reasonably equivalent or more secure access controls.

Ref: 16 CFR 314.4(c)(1), (c)(5)

Proof of Implementation: access-control policy; user/role list export; dated access-review record; MFA-enabled screenshot from each admin console, or the Qualified Individual’s written approval of equivalent controls.

Section 4. Asset and Data Management

The Firm shall identify and manage the data, personnel, devices, systems, and facilities that enable it to achieve its business purposes, in accordance with their relative importance to business objectives and the Firm’s risk strategy. The Firm shall maintain an inventory of its Information Systems and of the Customer Information it holds, accounting at minimum for the categories of sensitive information the Firm handles and the locations where that information is kept…

Page one of four documents. This is a single section — the full WISP runs to dozens of pages, and your packet also includes the Incident Response Plan, Acceptable Use Policy, and Access Control Policy, each tailored to your answers.

What’s in the full packet.

Written Information Security Plan (WISP)

Your firm's core security program, scaled to your size.

  • Every section cited to 16 CFR Part 314
  • Control-status summary: in place vs. in remediation
  • Proof-of-implementation checklist
  • IRS focus-area crosswalk for tax firms

Incident Response Plan

What to do, and who to call, in the first hour of a breach.

  • Severity levels and response deadlines
  • FTC, IRS, and state notification chain
  • Ransomware, wire-fraud, and lost-device playbooks
  • Fill-in emergency contacts table

Acceptable Use Policy

Day-to-day handling rules your staff can actually follow.

  • Email, device, and remote-work rules
  • Approved apps and generative-AI restrictions
  • Paper handling and secure disposal
  • A signed acknowledgment for each user

Access Control Policy

Who can reach client data, and on what terms.

  • Least-privilege and multi-factor authentication
  • Access reviews and prompt offboarding
  • Shared- and service-account controls
  • Physical access safeguards
Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.