The WISP Book Written Information Security Plans for small financial practices

About

A book that tells small firms to document their work should be able to document its own.

The review record

Before it was printed, the manuscript went through twelve rounds of review. Here is what came of them.

These figures describe the manuscript review completed for the first edition (Meridian) and carried unchanged into the second edition (Datum), and were last updated when the tenth round closed on August 21, 2026. A count on a page like this goes stale quietly, so it carries the edition it describes and the date it was set — the same standard the book applies to everything else it cites.

75 findings examined
136 edits applied and documented
18 proposed changes checked and rejected with reasons
4 questions still open, and named as open

The eleventh round closed on September 9, 2026, and a twelfth on September 10. It began as an outside second-opinion read of the manuscript; every claim it raised was checked against the issuing source before anything was changed. Fourteen findings were confirmed, three were rejected after checking, and three more were found in the process. The second edition also carries a full re-verification of every authority against its issuing source on September 7, 2026. All of it is logged on the update page, and the corrections that affect the first edition are listed there too.

The rejections are the part worth dwelling on. Ten proposed corrections were investigated and found to be wrong — and two of them, if applied, would have reintroduced errors that earlier rounds had already fixed. One reviewer quoted a passage from the book that does not exist in the book. Another cited a standard's table by a title that table does not have.

The lesson that came out of it is now a working rule: treat a critique aswhere to look, not what is wrong. Roughly half of the findings arrived with a mis-stated premise, a wrong section number, or an issue already fixed — and were still pointing at something real nearby. Verify before editing.

What the reviews found, in aggregate

A pattern held across every round, and it is a useful thing for any reader of compliance material to know: the explanatory chapters were right nearly every time; the forms, glossary entries, and callout boxes were where precision was lost.

Six defects were compression failures — a correct long passage restated short, dropping a qualifier on the way. Three times a correct warning existed but named the wrong location. One was a threshold that read “1,000 or more” where the statute says “more than 1,000,” because two adjacent subsections had been merged into a single table cell and the comparator carried across.

That is the error class this book is most vulnerable to, so it is the one that got a dedicated sweep: every appendix cell citing more than one provision, and every fill-in field that could invite a value the plan itself prohibits.

The one that stings

In September 2025 NIST withdrew SP 800‑88 Revision 1, superseded in its entirety. This project had recorded that standard as verified current — and had verified it from the very PDF carrying the withdrawal banner. The content was read carefully. Nobody checked whether the document was still live.

Two things came out of that. It is why the status page exists at all. And the lesson is given away free, at the top of that page'show to check it yourself section, because it is more useful in your hands than in ours.

What this project is not

The source status page Get in touch