Your written security plan, in about 15 minutes.
The FTC Safeguards Rule requires a written information security plan (a “WISP”). The IRS publishes a 28-page sample with blanks to fill in. Answer plain-English questions instead and get your plan filled in, with a to-do list for any gaps. Free, no signup, and your answers stay in your browser.
- 1Your firm
- 2Who’s responsible
- 3Where data lives
- 4Safeguards today
- 5Vendors & contacts
- 6Your plan
Got it.
We’ll email you within one business day to set up your review.
A real plan, not a pile of blanks.
Built on the structure of the IRS sample plan (Publication 5708) and the nine elements of the FTC Safeguards Rule (16 CFR 314.4).
- Objective, scope and the people responsible, including your Qualified Individual
- A written risk assessment from your own answers
- Your systems and data inventory
- Safeguards policies: access, multi-factor sign-in, encryption, passwords, Wi-Fi, remote access, disposal
- Vendor oversight, training and the annual review
- An incident response plan with the right notifications (FTC, IRS Stakeholder Liaison, your state)
- Attachments: retention policy, rules of behavior, breach checklist, staff sign-off, hardware and access lists
- A to-do list for every gap, with the fix
This tool creates a starting document from your answers. It is general information, not legal advice, and doesn’t make a business compliant by itself: you need to make it accurate, put the safeguards in place and review it at least yearly. Nothing you type is sent anywhere unless you choose to request a review.