The WISP Book Written Information Security Plans for small financial practices

A Written Information Security Plan for an office your size

Understand the requirements. Build the plan. Prove the work. Keep it current.
For tax preparers, bookkeepers, payroll providers, and other small financial practices.

The WISP Book, second edition, front cover
Reader checking a citation? Every law, publication, and standard the book cites is listed, dated, and monitored on Is This Still Correct? — the page printed in your copy at thewispbook.com/current.

The IRS gives away a template. Here is what it does not give you.

IRS Publication 5708 is free, and you should download it. It hands you the mandate and a set of blank forms. What it does not hand you is the part in between — what each requirement actually means in an office with four people and no IT department, which decisions are genuinely yours to make, and what to keep so you can show your work a year later.

A blank form does not tell you what to write in it. That gap is the book.

Free, and useful whether or not you buy anything

Is This Still Correct?

Every authority the book cites, with its edition, its status, and the date it was last checked. Including the one we are still unsure about.

The readiness check

Twelve questions, four minutes, and a list of where your gaps are. Runs in your browser; nothing is sent anywhere.

The reporting deadlines

Next business day, thirty days, ten days — which clock, which trigger, which authority. Print it and put it on the wall.

The threshold numbers

500, 5,000, more-than-1,000, two years, fifteen characters. What each one changes, and the provision that sets it.

Does this apply to me?

Where the duty actually comes from — and it is not where most summaries say it is. Sole practitioners, small firms, and the cases that are less obvious.

Common questions

Including the one nobody selling compliance material wants to answer plainly: if I buy this book, am I compliant?

Why you can trust what is in it

The manuscript has been through twelve rounds of review. Seventy-five findings have been examined. One hundred and thirty-six edits were applied. Eighteen proposed changes were checked andrejected with reasons, because they were wrong. Four questions remain open, and the book says which four. Where the printed first edition was wrong, the corrections are published and dated.

That record is public, because a compliance book that cannot show its own audit trail is asking you to take on faith the exact discipline it is selling you.The full account is on the About page.

The book will not make you compliant

No book will, and no website will either. Compliance is something your firm does, month after month, and then keeps evidence of. What a book can do is tell you what the requirements actually say, help you build a plan that fits an office your size, show you what evidence to keep, and — through this site — tell you when something it relies on has changed.

That is the whole offer. Anyone promising more than that is selling you something else.

The WISP Book, second edition, front cover