The WISP Book Written Information Security Plans for small financial practices

Is This Still Correct?

The book in your hands quotes laws, IRS publications, and technical standards. Those change. This page tells you which ones still say what the book says they say — and, when one changes, which section or appendix of the plan it affects.

Status of this page Tracks: The WISP Book, second edition (Datum) Last full check: September 7, 2026 Every source in the table below is checked each Monday for new editions, withdrawal notices, and dead links. Three destinations printed inside the plan are not in the table and are not checked weekly: the IRS Stakeholder Liaison page, the FTA’s breach reporting page, and IRS Form 14039‑B. All three were last checked September 10, 2026. There is a note on each below the table.

An update page with no date on it proves nothing. That includes ours. Every row in the table below carries the date its own source last changed, because a single date across a whole list tells you nothing about the row you actually care about.

One rule before you rely on anything here. This page tells you that something changed. The agency's own text is the proof. Every source is linked; follow the link before you act on it.

1. The standards the book cites

Eighteen rows: every source this page monitors, with the edition the book relies on and the date the source itself last changed. If a date in the last column falls after your copy was printed, that authority moved after your book did. One row is still unresolved and says so. If your copy of the book cites something that is not on this list, tell us — that is a gap in this page, not in your reading.

Every source this page monitors, with the edition the book relies on and when the source last changed.Every source below is rechecked every Monday. This table last changed September 14, 2026 and is current. A date that has not moved means the Monday check found nothing to change.
Source What the book cites Status Last changed Notes
15 U.S.C. § 6801
GLBA § 501
Pub. L. 106‑102 Current Jul 2010 Pub. L. 111‑203 The root obligation. Amended once, by Dodd‑Frank in 2010, which moved rulemaking authority to the CFPB for some institutions. The duty itself is unchanged since 1999.
26 U.S.C. § 7216 Current text Current 2019 Pub. L. 116‑25 The criminal-side complement to GLBA.
16 CFR Part 314
FTC Safeguards Rule
Current eCFR text Current May 13, 2024 eCFR versioner Breach reporting at § 314.4(j) effective May 13, 2024.
FTC, Safeguards Rule: What Your Business Needs to Know December 2024 update Current Dec 2024 The FTC's own plain-language guide.
IRS Pub 4557
Safeguarding Taxpayer Data
Rev. 6‑2024 Current Jun 2024 Its eight-character password advice is out of step with the current NIST standard, and calls eight characters “the NIST standard.” That was true under an older revision. The publication is current; that one sentence in it is stale.
IRS Pub 5708
Creating a WISP
Rev. 8‑2024 Current Aug 2024 The free Security Summit template.
IRS Pub 1345
Handbook for e-file Providers
The edition after November 2024 Edition not confirmed Not published The cover date does not survive text extraction from the PDF, and we have not confirmed a specific revision date on irs.gov. The current edition states that it replaces the November 2024 edition; the six security standards the book cites were read in the current file. We will not print a revision date we cannot confirm.
IRS Pub 3112
e-file Application and Participation
Current Current Nov 2025 Rev. 11‑2025 The monitoring and sanctions authority.
IRS Form W‑12
PTIN application and renewal
Rev. 10‑2025 Current Oct 2025 Line 11 asks whether you are aware of your data security responsibilities. It does not certify that you have a plan. The wording matters; see Does this apply to me?
NIST SP 800‑63B
Digital Identity Guidelines
Revision 4, final July 31, 2025 Current Jul 31, 2025 The Revision 3 page is still online and still returns the superseded text. If a source quotes a flat eight-character minimum, or the subtitle Authentication and Lifecycle Management, it is quoting Revision 3.
NIST SP 800‑88
Guidelines for Media Sanitization
Revision 2, September 2025 Current Sep 26, 2025 Revision 1 was withdrawn September 26, 2025 — superseded in its entirety. Its landing page now returns a 404 and the old PDF carries a withdrawal banner. This is the change that prompted this page; see corrections and how to check for yourself.
Fla. Stat. § 501.171 Through ch. 2026‑52 Current 2026 Amended by ch. 2026‑52 (SB 7026, Open Government Sunset Review Act). The amendment reaches § 501.171(11)(d) only — it defines “proprietary information” for the public-records exemption covering what a firm reports to the Department of Legal Affairs. Every threshold and clock the book prints was re-read in the amended text and is unchanged. Can change in any legislative session. If you practice outside Florida, your state's breach law governs and is not covered by this row.
Rev. Proc. 2007‑40 Current Current 2007 original, never superseded Section 7 is the authority for IRS monitoring and sanctions.
NISTIR 7621 Rev. 1
Small Business Information Security
Revision 1, November 2016 Current Nov 3, 2016 At nearly ten years old this is the oldest citation in the book, which makes it the likeliest candidate for a quiet withdrawal. Checked deliberately for that reason: still Final, no withdrawal or supersession banner. Now on the weekly watch.
IRS, Data Theft Information for Tax Professionals Current page Current Mar 26, 2026 page’s own date Page last updated March 26, 2026. Note the address: this page lives under /individuals/. The older /identity-theft-fraud-scams/ address now returns 404, and the book prints the working one.
IRS, Section 7216 Information Center Current page Current Sep 7, 2026 page’s own date The IRS landing page for the § 7216 disclosure and use rules. Monitored but not printed as a source in the book.
Federation of Tax Administrators
taxadmin.org
Bare domain Resolves Not tracked bare domain Watched only to confirm the host resolves and the breach-reporting resource still exists. A bare domain carries no change date.
FBI Internet Crime Complaint Center
ic3.gov
Bare domain Resolves Not tracked bare domain Watched only to confirm the host resolves. A bare domain carries no change date.

Why one row still says “edition not confirmed.” Because it is. Anyone can publish a table where every row reads “current.” The one row we are still unsure about is the evidence that the other seventeen were actually checked.

The three destinations that are not in the table. Each is printed inside the plan rather than in a source list, and one is a hyperlink whose address the book never prints. None is an authority the book cites, so none has a row above. All three were last checked September 10, 2026.

IRS Stakeholder Liaison contacts. Resolves. It groups contacts by region behind a single number rather than listing local ones. The plan’s wording was corrected in the second edition.

FTA, Report a Data Breach. Resolves, and now routes to individual state contacts. It no longer publishes the StateAlert address the book prints beside it. The IRS still does, on two Security Summit pages, so the contact card in the book is correct as printed.

IRS Form 14039‑B. Resolves at Rev. 5‑2021. Filed by mail, fax or in person, never online.

2. Corrections to the book

When something in the printed book turns out to be wrong, it is listed here: what it said, what it should say, which versions are affected, and the date of the fix.

September 10, 2026

Vendor terms of service were recorded by link, not by copy. Appendix G’s Vendor Review Record asked for a “Contract / ToS Reference (document name or URL)” and accepted a live address as the record of what a vendor promised. Chapter 6 already said the opposite: the terms are the written assurance, and the obligation is to have kept a copy. Published terms change without notice, so a current URL does not show what governed on the day the firm relied on it. Appendix G now requires a dated copy saved to firm records with the file name recorded, and Section 13 says so too. Affects the first edition (Meridian). Corrected in the second edition.

The Florida “no harm” determination had no place on the incident form. The book states the duty in three places, but Appendix B captured none of it — not the determination, not its five-year retention, not the filing. A firm could complete the incident log in full and still miss the filing, which forfeits the safe harbour. Appendix B now carries all three, and states the deadline precisely: the written determination goes to the Florida Department of Legal Affairs within 30 days after the determination, not 30 days after discovery (Fla. Stat. § 501.171(4)(c)). Those are different dates and can be weeks apart. Affects the first edition. Corrected in the second edition.

Three further second-edition changes are refinements, not corrections. The 24-hour firm policy is now stated as 24 calendar hours, with a note that this always falls on or before the next business day — so meeting firm policy satisfies the IRS rule in every case, including a Friday-afternoon discovery. Appendix B gained a communications log, to record the calls the contact card tells you to make. And Appendix D now asks for the BitLocker Key ID, which is the identifier a recovery screen shows when a machine will not boot and its Device ID cannot be looked up.

September 9, 2026

The IRS breach-notification email address. Section 15 and the Appendix B contact card told the reader to email the IRS Identity Theft Unit at identitytheft@irs.gov. The IRS page this book cites, Data theft information for tax professionals, publishes no email address for this report. The route is the Stakeholder Liaison, by phone, and the liaison notifies IRS Criminal Investigation on the firm’s behalf. Affects the first edition (Meridian). Corrected in the second edition. If you hold a first edition, strike that instruction and make the call.

The glossary understated the IRS deadline. The glossary entry for Stakeholder Liaison said the IRS sets no fixed deadline for tax professionals. Eleven other passages state the rule correctly: an Authorized IRS e-file Provider must report a confirmed security incident no later than the next business day after confirmation (IRS Pub 1345). The chapters were right and the glossary was wrong. Affects the first edition. Corrected in the second edition.

“MFA wherever available” understated the requirement. Seven passages conditioned multi-factor authentication on availability: Chapter 5, Section 11 of the plan, the quarterly compliance checklist in Appendix A (twice), the remote-access requirements in Appendix L, and the employee acknowledgment form in Appendix M (twice) — the last of these being the form staff actually sign. 16 CFR § 314.4(c)(5) requires MFA for any individual accessing any information system, and the only exception is reasonably equivalent or more secure controls approved in writing by the Qualified Individual. Availability is not the test. Affects the first edition. Corrected in the second edition.

The small-firm exemption was described as paperwork relief. § 314.6 excepts four provisions. Three are writing requirements. The fourth, § 314.4(d)(2), prescribes an annual penetration test and semiannual vulnerability assessments — tests a qualifying firm is excused from performing, not merely from recording. The book’s later discussion and its glossary had this right; the early summary did not. Affects the first edition. Corrected in the second edition.

The law-enforcement delay conflated two regimes. The Considerations chapter said the federal and Florida regimes both allow notice to be delayed on a law enforcement determination. They differ. Florida delays the notice itself (Fla. Stat. § 501.171(4)(b)). The federal rule does not delay your report to the FTC, which is still due within thirty days; it delays the Commission’s public disclosure, on a clock that starts from the date notice was provided (16 CFR § 314.4(j)). The plan’s own text was already precise; the chapter was not. Affects the first edition. Corrected in the second edition.

The Florida vendor clock did not subtract from yours. The book said a third‑party agent’s ten days “sits inside your thirty” and consumed a third of your window before your own clock started. Florida does not say that, and the sentence contradicted itself. Your deadline runs from your own determination or reason to believe, which most likely arises when the agent tells you. The statute does not settle it in so many words, so it is now stated as the open question it is. Affects the first edition. Corrected in the second edition, and added to Still open.

Four appendix instructions miscounted their own record blocks. Appendix J said six records, Appendix K three, Appendix N four and then three. Each provides two, with an instruction to duplicate the page. The guidance about how many records a period needs is useful and is kept; the implication that they were printed is gone. Affects the first edition. Corrected in the second edition.

Network equipment pointed at the printer log. Section 5 sent network equipment to Appendix Q, which is the Printer & Scanner Inventory Log. Network documentation belongs in Appendix E, where the rest of the book already sends it. Affects the first edition. Corrected in the second edition.

Two corrections are still being drafted, and are disclosed here rather than held back. The media-sanitization procedure in Section 17 tells the reader to perform a cryptographic erase by removing the BitLocker or FileVault key. Removing BitLocker’s last key protector does not erase anything — Windows stores a clear key so the volume stays readable. Separately, Section 12’s AES‑256 floor is stricter than the default configuration of both tools the book names: BitLocker device encryption defaults to XTS‑AES 128‑bit, and changing it requires decrypting the drive first. Both are with a security practitioner. Both affect the first edition. Until the replacement text is settled: do not treat “remove the key” as sanitization, and do not read the AES‑256 line as a finding that your existing BitLocker configuration is non-compliant.

The second edition (Datum) supersedes the first edition (Meridian). Four wording changes were made on September 7, 2026: the IRS Stakeholder Liaison instruction in Section 15 and Appendix B, a missing address on the FTC's Data Breach Response guide, and the two lines recording when the sources were last verified. Those four were edition changes rather than corrections — nothing the first edition stated was wrong when it was printed — and a reader holding the first edition can apply all four from this page. The entries above are a different matter. They are corrections, they affect the first edition, and a second edition existing does not reach anyone already holding the first.

The corrections applied before publication are a different matter, and they are not hidden. The book has been through twelve rounds of review; the count and the method are on the About page.

3. Still open

Four questions cannot be closed by checking a source today. The book says so, and so does this page.

Counting consumers toward the 5,000 threshold

Do dependents listed on a joint return count? Do the employees of a payroll client count? The FTC has published no counting method. The book takes the conservative reading and says openly that it is a reading, not settled law. This is a question for a GLBA attorney, and it is the one open item that no amount of source-checking will resolve.

The cover date on IRS Pub 1345

See the IRS Pub 1345 row in the table above. The publication's revision date does not survive text extraction from the PDF, and we have not confirmed a specific one on irs.gov. The current edition states that it replaces the November 2024 edition, and the six security standards the book cites were read in the current file — so the substance is verified even though the date is not. We will not print a revision date we cannot confirm, and the row will say edition not confirmed until we can.

When your thirty days starts, if a vendor tells you

Fla. Stat. § 501.171(6) gives a third‑party agent ten days to notify you. § 501.171(4)(a) gives you thirty days from your determination or reason to believe. The statute does not say in so many words whether your clock runs from the agent’s determination or from the day the agent reaches you. The reading here is that it runs from when you are told, because that is the reading that makes the two subsections consistent — but it is a reading, and it is one for a Florida attorney. Until it is settled, prefer vendors who commit in writing to faster notice.

Media sanitization, and the AES‑256 floor

Two technical passages are with a security practitioner rather than settled here; both are described under corrections. The sanitization question is which procedure actually achieves a cryptographic erase on a given class of device. The encryption question is narrower: Apple’s Platform Security documentation is where FileVault’s key length is stated, that wording has not been retrieved, and so whether “AES‑256” is loose shorthand or a misstatement is not yet decided. Neither is answered by asserting something here.

4. How to check any of this yourself

You should not have to take our word for it, and this page will eventually be out of date between checks. Here is the method, which is worth more than the table.

  1. Look for a withdrawal banner before you read a word of the document. NIST leaves superseded publications online. The old file opens normally, reads authoritatively, and is wrong. This is the lesson that cost us a correction: we verified a standard's contents from the very PDF that carried its withdrawal notice. Check whether the source is still live first, then read it.
  2. Compare the revision number, not the title. “SP 800‑88” and “SP 800‑88 Rev. 2” are not the same citation. A source that names a standard without naming its revision has not checked the revision.
  3. For regulations, read the eCFR, not a summary. The eCFR is the current text. Guides and articles — this one included — are restatements.
  4. For IRS publications, check the revision code on the cover (for example, “Rev. 6‑2024”), and download from irs.gov rather than from a search result.
  5. For state law, check the session. A statute page usually names the last legislative chapter incorporated. If your state's legislature has met since then, the page may lag.
  6. Confirming that a claim is current is not the same as confirming it was ever right. We learned this one the expensive way: a check confirmed that a sentence had survived a standard's new revision, without ever asking whether the sentence had been correct in the first place. It had not been.

5. Change log

Newest first. Every entry is dated. Entries describe what changed at the source, not what changed on this website.

September 19, 2026

The second edition is published. The WISP Book, second edition (Datum), 190 pages, ISBN 979‑8‑175‑62681‑1. It supersedes the first edition (Meridian).

This entry records the book, not a source. Nothing changed at any watched authority today. It is here because every correction listed above names the edition it affects, and a reader holding a copy needs to know which edition that is. The two entries still described as pending — the media‑sanitization procedure and the AES‑256 floor — remain pending, and the text they concern is unchanged in both editions.

September 10, 2026

All twenty watched destinations verified. Nothing changed at any source. Every edition the book states is still current: Pub 4557 Rev. 6‑2024, Pub 5708 Rev. 8‑2024, Pub 3112 Rev. 11‑2025, Form W‑12 Rev. October 2025, SP 800‑63B Revision 4, SP 800‑88 Revision 2, NISTIR 7621 Revision 1, and the FTC guide at December 2024. 16 CFR Part 314’s own last amendment is still May 13, 2024, read from the eCFR versioner rather than the page banner. Florida § 501.171’s history line ends at ch. 2026‑52, which is what this page already records.

The last two never-verified destinations were checked. IRS Form 14039‑B is at Rev. 5‑2021, filed by mail, fax or in person and never online. The FTA’s Report a Data Breach page resolves but no longer publishes StateAlert@taxadmin.org, routing instead to individual state contacts. The address is not dead — the IRS still publishes it in two Security Summit pages, so the contact card in the book is correct as printed and no correction is owed. All twenty destinations have now been verified at least once.

Row dates above move to September 10. The full-check stamp does not. A full check also asks whether anything is missing that should be cited at all, and that half was not run today.

September 10, 2026

A twelfth round, from a second outside read. Every regulatory and technical claim was checked against the issuing source before anything was changed. Two corrections affecting the first edition are listed above, with three refinements. Five of the reviewer’s claims did not survive checking — among them a Florida citation that named both the wrong subsection and the wrong trigger date, and a reported gap in the password exception path that was already covered in full. Two errors of our own from round 11 were also found and fixed: a correction sweep that had reached four of seven passages, and a broken cross-reference in the Chapter 9 map, which is the mechanism built to detect exactly that. The source table is unchanged. This was a review of the manuscript, not of the sources, so the September 7 verification date above still means what it says.

September 9, 2026

An eleventh round of review, prompted by an outside read. The manuscript was put through a second-opinion review by another AI system, and every regulatory and technical claim it raised was checked against the issuing source rather than accepted. Fourteen findings were confirmed and corrected, three of its claims did not survive checking and were rejected, and three defects it had missed were found along the way. Eight corrections affecting the first edition are listed above, and two more are disclosed there as still being drafted. The correction above was itself incomplete when first applied, and that is recorded here rather than quietly repaired. The MFA fix initially reached four of seven passages, because the search that found them matched “wherever available” and “where available” but not “wherever it is available”, “where supported” or “if MFA available”. The remaining three — two in the employee acknowledgment form, one in the quarterly checklist — were found the same day by a second outside review and corrected. It is the registry’s own failure pattern: a phrasing restated by hand, and a grep that matched the wording it expected. The source table is unchanged. This was a review of the manuscript, not of the sources, so the September 7 verification date above still means exactly what it says.

September 7, 2026

Florida amended § 501.171. Ch. 2026‑52 (SB 7026, Open Government Sunset Review Act) reaches subsection (11)(d) only, defining “proprietary information” for the public-records exemption that covers what a firm reports to the Department of Legal Affairs. Every threshold and clock the book prints — 500 residents, 30 days, the 15‑day extension, more than 1,000 for the consumer reporting agencies, the third‑party agent's 10 days — was re-read in the amended text and is unchanged. Nothing in the book needs correcting; the row above now records the new chapter.

The IRS Stakeholder Liaison page no longer lists local numbers. One of the three destinations that sit inside the plan rather than in a source list, and never checked until now. It resolves, but it groups contacts by region behind a single number. The plan told the reader to find a local number there, and that wording was corrected in the second edition.

An open question closed — by the manuscript, not by a source. Rev. Proc. 2012‑32 is no longer cited anywhere in the book. Appendix K names IRS Pub 1345 as the basis for the three-year retention of Forms 8879 and 8878, which is the correct authority and matches Pub 1345's own wording. The table row and the open item are both gone.

Everything else came back clean against its issuing source. One trap worth recording: the eCFR page for Part 314 reports a “last amended” date belonging to Title 16, not to Part 314, which is unchanged since May 13, 2024. Read off the banner it looks like an amendment every week.

August 21, 2026

A full check of every authority came back clean — every revision date, edition and effective date the book prints still matches its issuing source, and no withdrawal or supersession banner appeared on any of them. Two things changed here rather than in the book. The watch was widened from the fourteen authorities to every URL the book prints, after four printed links were found never to have been on the list; the oldest of them, NISTIR 7621 Rev. 1 from November 2016, was checked for the first time and is still Final. And the IRS Data Theft Information for Tax Professionals page was retrieved at last: the address recorded on the watch list had moved, which is why earlier attempts returned nothing. The book was already printing the working address.

September 26, 2025

NIST withdrew SP 800‑88 Revision 1, superseded in its entirety by Revision 2 (September 2025). The three sanitization actions — Clear, Purge, Destroy — are unchanged, but their definitions moved from § 2.5 to § 3.1, the certificate of sanitization moved to § 4.6 and Appendix C, and Appendix A is now the glossary. Revision 2 also points to IEEE 2883 for per-media purge techniques and warns against carrying magnetic-media overwrite habits to flash storage. If your disposal log cites Revision 1 or its section numbers, update the citation.

July 31, 2025

NIST SP 800‑63B Revision 4 published final, superseding Revision 3 (March 2, 2020). Passwords used as a single factor must now be at least 15 characters; 8 remains the floor for a password used within multi-factor authentication. Composition rules and periodic forced rotation moved from “should not” to “shall not.” The Revision 3 page remains online and still returns the old text.

May 13, 2024

The FTC Safeguards Rule breach-reporting provision, § 314.4(j), took effect (88 FR 77509, November 13, 2023). See the reporting deadlines.


Something on this page wrong or out of date? Tell us. Corrections to this page are made the same week.