Bookings[email protected] San Antonio · Texas
Free tool · Tax pros, CPAs, dealers & lenders

Your written security plan, in about 15 minutes.

The FTC Safeguards Rule requires a written information security plan (a “WISP”). The IRS publishes a 28-page sample with blanks to fill in. Answer plain-English questions instead and get your plan filled in, with a to-do list for any gaps. Free, no signup, and your answers stay in your browser.

  1. 1Your firm
  2. 2Who’s responsible
  3. 3Where data lives
  4. 4Safeguards today
  5. 5Vendors & contacts
  6. 6Your plan
Step 1 of 5Your firm
What kind of business are you?
Legal business name
Doing business as optional
City
State
People with access to client data
Client records you keep (current and past)

Your answers are saved only in this browser, so you can come back later.

What you get

A real plan, not a pile of blanks.

Built on the structure of the IRS sample plan (Publication 5708) and the nine elements of the FTC Safeguards Rule (16 CFR 314.4).

  • Objective, scope and the people responsible, including your Qualified Individual
  • A written risk assessment from your own answers
  • Your systems and data inventory
  • Safeguards policies: access, multi-factor sign-in, encryption, passwords, Wi-Fi, remote access, disposal
  • Vendor oversight, training and the annual review
  • An incident response plan with the right notifications (FTC, IRS Stakeholder Liaison, your state)
  • Attachments: retention policy, rules of behavior, breach checklist, staff sign-off, hardware and access lists
  • A to-do list for every gap, with the fix

This tool creates a starting document from your answers. It is general information, not legal advice, and doesn’t make a business compliant by itself: you need to make it accurate, put the safeguards in place and review it at least yearly. Nothing you type is sent anywhere unless you choose to request a review.