A written information security program (WISP) is the documented set of policies, procedures, roles, and safeguards an organization uses to protect the information it holds, written down so people can follow it, review it, and show it to others.
The term is common shorthand in legal, insurance, and customer security reviews. Some laws require a written program without using the acronym. The FTC Safeguards Rule and the Massachusetts data security regulation both call for a "comprehensive information security program" that is "written in one or more readily accessible parts." The IRS uses the same acronym for a written information security plan in its guidance for tax professionals.
In simple terms, a WISP answers:
- What information do we protect, and where does it live?
- Who is responsible, and which safeguards do we run?
- How do we test, review, and update the program over time?
This page defines the term. For a step-by-step guide to building and maintaining one, see Building a Written Information Security Program (WISP). For the top-level policy document that usually sits inside a WISP, see What Is an Information Security Policy?.
Why a WISP Matters
A security program that lives only in people's heads breaks when the team grows, a key person leaves, or a customer asks for proof.
A WISP matters because:
- Some organizations are legally required to keep a written program, depending on their industry and the data they hold.
- Customers, partners, and insurers often ask for it during security reviews.
- It gives staff one place to find the rules for access, data handling, vendors, and incidents.
- It names the people responsible, so decisions do not stall.
- It gives auditors and assessors a baseline to compare against what actually happens.
A WISP is only useful if it matches reality. A polished document that nobody follows can create more risk than a short one the team actually uses.
What a WISP Usually Includes
Contents vary by law, industry, and size. Most WISPs cover these elements:
- Scope. The systems, data types, locations, and people the program covers.
- Responsible person. A named individual or role who oversees the program.
- Risk assessment. How the organization identifies and evaluates risks to the information it holds. See risk assessment.
- Safeguards. Administrative, technical, and physical controls, such as access control, multi-factor authentication, and encryption.
- Workforce rules. Policies, procedures, security awareness training, and discipline for violations.
- Service provider oversight. How vendors are selected, contracted, and reviewed.
- Incident response. How the organization responds to and documents security events. See incident management.
- Testing and review. How safeguards are monitored and how often the program is reviewed and updated.
Where WISP Requirements Come From
This section summarizes public sources. It is not legal advice. Whether a specific law applies to you depends on your facts, so confirm with counsel.
FTC Safeguards Rule (16 CFR Part 314)
The FTC Safeguards Rule applies to financial institutions under FTC jurisdiction, a group that includes many non-bank businesses such as mortgage brokers, finance companies, and check cashers. Section 314.3 requires a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards suited to the organization's size, complexity, activities, and the sensitivity of customer information.
Section 314.4 lists required elements. They include designating a Qualified Individual, basing the program on a written risk assessment, implementing safeguards such as access controls, encryption, and multi-factor authentication, regularly testing or monitoring safeguards, training staff, overseeing service providers, keeping a written incident response plan, and having the Qualified Individual report in writing at least annually to the board or a senior officer. Section 314.6 exempts institutions that hold customer information on fewer than 5,000 consumers from some of these elements. The FTC also publishes a plain-language guide: FTC Safeguards Rule: What Your Business Needs to Know.
Massachusetts 201 CMR 17.00
The Massachusetts regulation 201 CMR 17.00 applies to persons that own or license personal information about Massachusetts residents. Section 17.03 requires a comprehensive information security program written in one or more readily accessible parts. Required elements include designating employees to maintain the program, assessing risks, overseeing service providers, regular monitoring, and reviewing the scope of security measures at least annually or after a material change in business practices. Section 17.04 adds computer system security requirements, such as encrypting personal information on laptops and when transmitted across public networks.
IRS guidance for tax professionals
IRS Publication 5708 explains that tax and accounting professionals are treated as financial institutions under the Gramm-Leach-Bliley Act and the Safeguards Rule, and it offers a sample written information security plan template.
Contracts, insurers, and customers
Even when no statute applies, a contract, cyber insurance application, or customer security questionnaire may ask whether you maintain a WISP. In those cases, the request usually means a documented, owned, and current security program.
WISP vs Related Terms
| Term | What it is | How it relates to a WISP |
|---|---|---|
| Information security policy | Top-level document stating security principles and roles | Usually one part of the WISP, not the whole program |
| WISP | The written program: policies, procedures, roles, safeguards, and review cycle | The umbrella documentation |
| Information security program plan | NIST term for a formal document describing an organization-wide security program | A close equivalent in federal and NIST-aligned settings |
| ISMS | The management system that ISO 27001 defines for running security | Broader management system; a WISP can serve as part of its documentation |
| SOC 2 report | An independent auditor's report on controls at a service organization | Tests whether controls operated; does not certify a WISP or legal compliance |
NIST defines an information security program plan as a formal document that provides an overview of the security requirements for an organization-wide information security program and describes the program management controls and common controls in place or planned for meeting those requirements.
How a WISP Relates to SOC 2
SOC 2 does not use the term WISP and does not require a document with that name. The AICPA 2017 Trust Services Criteria with revised points of focus (2022) do expect documented direction. For example, CC5.3 addresses deploying control activities through policies that establish what is expected and procedures that put those policies into action.
In practice, many SaaS companies use their WISP or policy library as the written foundation for SOC 2. Auditors then test whether the controls it describes actually operated. For a SOC 2 Type 2 report, that means evidence across the audit period, not just an approved document. A SOC 2 report also does not confirm that your WISP satisfies the FTC rule, Massachusetts law, or any other statute. See What Is SOC 2?.
Evidence That a WISP Is Real
| Element | Example evidence |
|---|---|
| Approval | Approved version with date and approver |
| Responsible person | Named designation in the document or a governance record |
| Risk assessment | Dated written assessment and follow-up actions |
| Workforce awareness | Policy acknowledgement and training completion records |
| Service providers | Vendor reviews and contracts with security terms |
| Testing and monitoring | Scan results, test reports, or monitoring records |
| Review cycle | Annual review notes and change history |
For the full build process, see the WISP resource and Policy Acknowledgement Evidence for SOC 2.
Common Misconceptions
- "A WISP is one PDF." It can be one document, but the laws above allow "one or more readily accessible parts." What matters is that it is complete and current.
- "A template is enough." Templates help, but a WISP must describe your systems, data, and people.
- "A SOC 2 report means we have a compliant WISP." SOC 2 tests controls against the Trust Services Criteria. It does not decide legal compliance.
- "We wrote it once." Both the FTC rule and the Massachusetts regulation expect ongoing monitoring, review, and updates.
- "Only large companies need one." Applicability depends on the data you hold and the laws that cover you, not only on size.
How AuditFlo Helps
AuditFlo (auditflo.co) helps teams retain continuous evidence collection and audit-period history for operational artifacts when those records are stored or linked through connected systems and workflows your team already uses, such as GitHub and Jira.
For a WISP, that can mean dated history showing that the access, change, and review controls your written program describes actually operated. Your policy library or GRC platform remains the home for the WISP itself. AuditFlo does not write or approve your WISP, does not provide legal advice, does not determine whether a law applies to you, does not issue SOC 2 reports, does not certify compliance, and does not replace auditors or counsel.
To see the workflow for your stack, request a demo.
Key Takeaway
A written information security program (WISP) is the documented set of policies, procedures, roles, and safeguards an organization uses to protect information. Some laws, such as the FTC Safeguards Rule and Massachusetts 201 CMR 17.00, require a written program for covered organizations, and many customers and insurers ask for one. A WISP is only as strong as its match with reality, so keep it scoped, owned, reviewed, and backed by evidence that its controls operate.