The full template. Highlighted blanks fill in when you
Personalize; whatever's left stays a [bracket] for you to complete.
Purpose
This Written Information Security Plan (the "Plan") documents how [Organization Name] ("[Short Name]") protects the security, confidentiality, and integrity of the client and taxpayer information in its care. It is intended to meet the obligation, applicable to paid tax preparers and financial-services firms, to maintain a written, risk-based information security program under applicable law and the standards of your firm's regulators, including the FTC Safeguards Rule and IRS guidance.
This Plan is a working document. It is designed to be reviewed and adjusted as [Short Name] grows, adopts new technology, or faces new threats.
Scope
This Plan applies to all nonpublic personal information and taxpayer data that [Short Name] collects, receives, creates, stores, transmits, or disposes of, in any format. It applies to every partner, owner, employee, contractor, and temporary or seasonal worker who has access to that information, and it governs all systems, devices, and physical locations where client data resides, including [Where Client Data Is Stored].
Definitions
- Client Data / Nonpublic Personal Information (NPI): Any personally identifiable financial or tax information a client provides, that is generated from a transaction, or that [Short Name] otherwise obtains, that is not publicly available.
- Qualified Individual: The person designated to be accountable for the security program.
- Service Provider: Any outside vendor that receives, stores, or processes client data on the firm's behalf.
Designation of a Qualified Individual
[Short Name] designates [Qualified Individual / Security Coordinator] as the Qualified Individual responsible for overseeing, implementing, and enforcing this Plan. This person coordinates risk assessments, employee training, vendor oversight, and incident response, and reports periodically to firm leadership on the state of the program.
Risk Assessment
[Short Name] performs a written risk assessment [Risk Assessment Frequency] and after any significant change to its operations or systems. The assessment identifies reasonably foreseeable internal and external risks to the confidentiality, integrity, and availability of client data, evaluates the likelihood and potential damage of each risk, and assesses the sufficiency of existing safeguards. Identified risks are prioritized and tracked to remediation.
Safeguards
Access Controls. Access to client data is limited to personnel who need it to perform their duties. Each user has a unique account. Multi-factor authentication is required for remote access and for systems holding client data. Access rights are reviewed periodically and revoked promptly when a person leaves or changes roles.
Encryption. Client data is encrypted in transit and at rest wherever technically feasible, including on laptops, portable media, and backups. Email containing client data is sent through a secure or encrypted channel.
Data Inventory and Minimization. [Short Name] maintains an inventory of where client data is collected, stored, and transmitted, and collects only the information reasonably needed to serve the client.
Device and Network Security. Firm systems use supported operating systems, current security patches, reputable anti-malware protection, and a properly configured firewall. Default and vendor passwords are changed before use.
Secure Disposal. Client data is retained only as long as needed for business or legal purposes and is then destroyed securely, in accordance with the firm's records retention policy.
Change Management and Monitoring. [Short Name] evaluates the security impact of new systems and monitors for unauthorized access to client data.
Oversight of Service Providers
Before engaging a service provider that will handle client data, [Short Name] confirms the provider is capable of maintaining appropriate safeguards, requires the provider by contract to protect the data, and periodically reassesses the provider's continued fitness.
Employee Training and Management
All personnel receive security awareness training at hire and periodically thereafter, including how to recognize phishing and social engineering. Personnel are instructed to report suspected incidents immediately to the Qualified Individual.
Incident Response
[Short Name] maintains a written incident response plan that governs detection, containment, investigation, notification, and recovery. Any suspected or actual security incident must be reported to [Qualified Individual / Security Coordinator] without delay, and to affected clients, the IRS, and other authorities as required by applicable law.
Roles & Responsibilities
- Firm leadership approves this Plan, allocates resources, and receives periodic reporting.
- The Qualified Individual implements, monitors, and updates the Plan.
- All personnel follow the Plan and report suspected incidents promptly.
Employee Acknowledgment
Each person with access to client data must sign an acknowledgment that they have read, understood, and agree to follow this Plan. Signed acknowledgments are retained by [Short Name].
Enforcement
Failure to follow this Plan may result in disciplinary action up to and including termination of employment or contract, and may be reported to authorities where required.
Review & Revision
This Plan is owned by [Policy Owner], [Owner's Title], and takes effect on [Effective Date]. It will be reviewed no later than [Firm's Next Review Date] and after any material change to the firm's operations, systems, or threat environment. Questions may be directed to [Contact Email].