Risk Assessment
Identify where sensitive information exists and the risks associated with the systems and processes that handle it.
ACC Inc. helps businesses develop and maintain Written Information Security Plans that connect policies, technical safeguards, employee responsibilities, and day-to-day operations.
Businesses that collect, store, transmit, or otherwise handle sensitive personal or financial information may be required to maintain a written information security program.
This is especially relevant to organizations handling tax records, financial information, customer data, employee information, and other sensitive records.
A WISP should reflect how the organization actually operates. The policies on paper and the safeguards in the technology environment need to support each other.
A WISP is more than a document. It should define how sensitive information is protected throughout the organization.
Identify where sensitive information exists and the risks associated with the systems and processes that handle it.
Establish appropriate access controls, account management, and authentication safeguards.
Protect workstations, networks, remote access, endpoints, and other systems that handle sensitive information.
Address storage, transmission, backup, recovery, retention, and secure handling of sensitive information.
Define employee responsibilities, training expectations, and appropriate oversight of service providers.
Document security responsibilities, incident procedures, reviews, and the process used to maintain the program.
Identify sensitive information, systems, users, vendors, and applicable requirements.
Review current safeguards, policies, practices, and documentation.
Address technical gaps and develop the written policies and procedures that support the security program.
Keep the WISP, safeguards, and supporting documentation current as the business and technology environment change.
WISP requirements are especially relevant to organizations that collect, store, or transmit sensitive customer or financial information.
Businesses handling tax records, Social Security numbers, financial documents, and other sensitive client information.
Firms responsible for protecting financial records and confidential client information.
Organizations handling customer financial information and other regulated data.
Evaluate the current security program and identify missing elements.
Document systems, sensitive information, risks, and existing safeguards.
Implement practical security improvements where gaps are identified.
Create and organize the written documentation supporting the program.
Review how sensitive information is collected, uploaded, transmitted, and protected.
Help maintain the program as systems, vendors, staff, and requirements change.
ACC Inc. can review your current environment, identify gaps, and help turn your security requirements into a practical working program.