Compliance Free Assessment Services Blog Contact Client Portal
IRS Publication 4557 · GLBA Compliance

Written Information Security Plan Generator

Complete each section to generate your WISP document. Your compliance score is calculated in real-time. A score of 85% or higher is required for a compliant plan.

01
Business Information
02
Data Inventory & Scope
15 pts
Why this matters: The IRS requires you to document what client data you collect, where it is stored, and how it flows through your systems.
Acknowledgment of client data types covered under IRS Publication 4557.
5 pts
Includes computers, servers, cloud drives, USB drives, filing cabinets, and any third-party systems.
5 pts
Examples: tax software providers, cloud storage, payroll services, printing companies.
5 pts
03
Access Controls & Authentication
20 pts
IRS Requirement: Multi-Factor Authentication (MFA) on all systems accessing client data is mandatory under Publication 4557.
This is a non-negotiable IRS requirement. Applies to email, cloud storage, and tax software.
8 pts
No shared credentials. Passwords must include upper/lowercase, numbers, and symbols.
4 pts
Admin rights are limited. Access is revoked immediately upon employee departure.
4 pts
Prevents unauthorized access when workstations are left unattended.
4 pts
04
Data Protection & Encryption
20 pts
BitLocker or FileVault enabled. Cloud storage uses encryption by default.
6 pts
No unencrypted email attachments with PII. Secure portals or encrypted email required.
6 pts
Backups tested quarterly. Off-site or cloud copy maintained.
4 pts
Paper records shredded. Digital records securely wiped (not just deleted).
4 pts
05
Employee Security Training
15 pts
Note: If building a compliant security training program is beyond your capacity, Preeminent Technologies can build and deliver it for you.
Covers phishing, password hygiene, data handling, and suspicious activity.
6 pts
Retained in employee files. New hires sign before accessing client data.
5 pts
Clear escalation path. IRS notification within 72 hours when required.
4 pts
06
Incident Response Plan
15 pts
Includes identification, containment, eradication, recovery, and notification.
6 pts
IRS: 1-800-908-4490. FTC: ReportFraud.ftc.gov. IT provider on speed-dial.
5 pts
Review log maintained. Triggered by major business or system changes.
4 pts
07
Physical & Environmental Security
10 pts
Keys limited to authorized staff. After-hours access restricted.
5 pts
Privacy screens used in client-facing areas.
5 pts
08
Network & Device Security
5 pts
Auto-updates enabled. Weekly scans configured.
3 pts
Prevents unauthorized access to internal systems via guest network.
2 pts
WISP COMPLIANCE SCORE
0%
Complete the sections above to calculate your score.