Disclaimer
The short version: this is general information, carefully checked and still capable of being wrong or out of date. It is not legal advice, and no book or website can make your firm compliant.
Not legal advice#
The WISP Book and this website provide general information about federal and state information security requirements. They do not provide legal advice, tax advice, or professional security consulting. Reading this site, buying the book, or corresponding with us does not create an attorney‑client relationship or any other professional relationship.
Whether a particular requirement applies to your practice can turn on facts that neither the book nor this site can know. Coverage under the FTC Safeguards Rule is activity-based and jurisdictionally bounded; firms answering to a different regulator under GLBA § 505 are governed by a different rulebook. For advice about your specific situation, consult an attorney licensed in your jurisdiction who practices in this area.
No guarantee of compliance#
Adopting the plan in the book, completing its appendices, or acting on anything published here does not guarantee compliance with the Gramm‑Leach‑Bliley Act, the FTC Safeguards Rule, IRS e‑file requirements, any state law, or any other legal obligation.
Compliance consists of what your firm actually does and can demonstrate. A completed document describing controls you have not implemented is not compliance; it is a written record of the opposite.
Accuracy and currency#
Every legal citation in the book and on this site was checked against the primary source on the date recorded. Laws, regulations, agency publications, and technical standards change, and sometimes they are withdrawn without the old version leaving the internet.
The source status page records the current status and last-checked date of every authority the book relies on, and names the items we have not been able to confirm. It is maintained on a published schedule, and it will still sometimes lag a change.
Before you rely on any requirement stated here, verify it against the primary source. Every source is linked. The update page tells you something changed; the agency's own text is the proof.
The readiness check#
The readiness check is a twelve-question self-assessment intended to help you identify gaps. It is not an audit, an assessment of compliance, or a determination of your legal obligations. Twelve questions cannot evaluate a rule with nine program elements. A result showing no gaps does not mean your program is adequate.
Third-party links and materials#
This site links to materials published by the FTC, the IRS, NIST, Congress, and state legislatures. We do not control those sites and are not responsible for their content or availability. Links are provided so you can verify what we say against what they say.
Limitation of liability#
The book and this site are provided on an “as is” basis, without warranties of any kind, express or implied, including any warranty of accuracy, completeness, fitness for a particular purpose, or non-infringement. To the fullest extent permitted by law, we are not liable for any loss or damage arising from reliance on the book or this site, including regulatory penalties, business interruption, data loss, or consequential damages.
This disclaimer corresponds to the disclaimer printed in the book. Where they differ in wording, both are intended to say the same thing: verify the source, and get advice about your own situation from someone qualified to give it.