A one-page summary of what the Safeguards Rule asks of your staff, with the primary citations, a six-question self-check, and the records worth keeping on file.
Owners and managing partners of small tax and accounting practices who already know they need a written information security plan, and who want to know whether the training and personnel portion of theirs would hold up.
It is deliberately short. One page, so it can sit next to your plan rather than replace it.
Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, tax and accounting professionals are treated as financial institutions regardless of size, and the IRS states plainly that a written plan is required by law rather than merely advisable.1
Most firms get the document written. The training and personnel section is usually where it thins out into a single sentence of intent, with no schedule, no coverage list, and no completion records behind it.
It is also one of the few elements with no small-firm relief. Under 16 CFR 314.6, a firm holding customer information on fewer than five thousand consumers is relieved of the written risk assessment, of continuous monitoring or annual penetration testing, of the written incident response plan, and of the annual written report to a governing body.2 The personnel and training paragraph at 314.4(e) is not among them.3
Not legal advice, and not a compliance product. CyberNest is a security practitioner, not a law firm. This summary explains an obligation and points you at the primary text. It does not tell you whether your firm complies, and no training program, ours included, delivers compliance with the Safeguards Rule or protects against every incident.
If you would rather read than download, the full write-up is on the blog: What the WISP Requirement Actually Asks of Your Staff. The one-pager is the condensed version of the same material, formatted to print.
Fill this in and the download opens on the next page, so there is nothing to wait for in your inbox. We will let you know when new resources publish, and you can unsubscribe from any email we send.