

WRITTEN INFORMATION SECURITY PLAN (WISP)
E.P. Tax Consultants
Effective Date: 11/29/25
Last Updated: 11/29/25
1. Purpose
The purpose of this Written Information Security Program (WISP) is to establish administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and security of all sensitive data handled by E.P. Tax Consultants. This includes client tax information, financial records, identifying information, login credentials, and any other data governed under federal and state privacy laws.
2. Scope
This WISP applies to:
-
All employees, contractors, interns, and temporary staff
-
All systems, devices, networks, and software owned or utilized by E.P. Tax Consultants
-
All client data in electronic or physical form
-
Any third-party service providers with access to client information
3. Data Classification
To ensure proper protection, covered information is classified as follows:
A. Confidential Data
Includes but is not limited to:
-
Tax returns and supporting documents
-
Social Security numbers
-
Banking information
-
Business financials
-
Payroll records
-
Personal identifying information (PII)
B. Internal Data
-
Internal communications
-
Firm procedures
-
Training materials
C. Public Data
-
Marketing materials
-
Website content
-
Public financial statements (if applicable)
4. Administrative Safeguards
4.1 Access Control
-
Access to client data is restricted based on job role.
-
Multi-factor authentication (MFA) is required for all logins.
-
Access rights are reviewed quarterly.
4.2 Employee Training
-
Staff must complete annual security and confidentiality training.
-
New employees must sign confidentiality and data-handling agreements.
4.3 Background Checks
-
All staff with access to sensitive data must pass a background check.
4.4 Confidentiality Agreements
-
Employees and contractors sign NDAs before accessing E.P. Tax Consultants’ information or client data.
5. Physical Safeguards
5.1 Secure Workspaces
-
Offices of E.P. Tax Consultants must remain locked outside business hours.
-
Sensitive documents must be stored in locked filing cabinets.
5.2 Device Controls
-
Company laptops must use password protection and encryption.
-
Removable media (USBs, external drives) are prohibited unless encrypted and approved.
5.3 Visitor Access
-
Visitors must be escorted at all times.
-
No unauthorized individual may access client files or systems.
6. Technical Safeguards
6.1 Network Security
-
Firewalls and endpoint protection are required on all systems.
-
Wi-Fi networks must use WPA3 encryption.
-
Public Wi-Fi use requires a company-approved VPN.
6.2 Data Encryption
-
All client data must be encrypted at rest and in transit.
-
Email containing sensitive data must use secure portals or encrypted attachments.
6.3 Password Policy
-
Minimum 12 characters, strong password requirements
-
Passwords must be changed every 90 days
-
Password reuse is prohibited
6.4 Data Backups
-
Daily encrypted backups of all systems
-
Off-site or cloud backups must meet IRS Publication 1075 standards
-
Backups tested quarterly
7. Third-Party Vendor Management
-
Vendors handling client information for E.P. Tax Consultants must sign a Data Protection Agreement.
-
Vendors must provide proof of cybersecurity controls and compliance.
-
Vendor access reviewed annually.
8. Data Retention & Disposal
8.1 Retention
-
Client tax records retained per IRS and state regulations.
-
Internal business records kept per accounting industry standards.
8.2 Disposal
-
Paper documents shredded using a cross-cut shredder or certified destruction service.
-
Electronic data securely wiped using NIST-compliant methods.
9. Incident Response Plan
9.1 Identification
Employees must immediately report:
-
Suspicious emails
-
Unauthorized access
-
Lost or stolen devices
-
Data breaches
9.2 Containment
-
Compromised accounts are disabled immediately
-
Systems isolated until cleared
-
Forensic analysis performed if needed
9.3 Notification
If a breach occurs, E.P. Tax Consultants will notify:
-
Affected clients
-
Applicable federal and state agencies
-
Insurance carriers (cyber liability coverage)
All notifications will meet legal and regulatory timeframes.
10. Policy Enforcement
Failure to comply with this WISP may result in:
-
Disciplinary actions
-
Access restrictions
-
Contract termination (for contractors or vendors)
11. Review & Updates
This WISP will be reviewed annually and revised when there are:
-
Regulatory changes
-
New technologies adopted
-
Security incidents
-
Organizational changes
ACKNOWLEDGMENT & AGREEMENT
I acknowledge that I have received, read, and understand the Written Information Security Plan (WISP) for E.P. Tax Consultants. I agree to follow all policies and procedures outlined in the document.
Employee Name: E'Marion Powell
Signature: E'Marion C Powell
Date: November 29, 2025
PDF LINK FOR POLICY
Written Information Security Plan
_edited_edited_edited.png)
_edited_edited.png)
