What is WISP (Written Information Security Program)?

A WISP is a single written document describing how your organization protects sensitive information - required by FTC Safeguards, often by security reviewers, and the foundational document SOC 2 + HIPAA audits expect to see first.

A WISP isn't a specific format mandated by law - it's a document that demonstrates the existence of your security program. Auditors and reviewers want to see administrative, physical, and technical controls; a designated security officer; an incident response plan; vendor risk management; and an annual review schedule.

Most security renewal questionnaires in 2026 ask whether you have a WISP and request a copy. A missing WISP makes every security review slower because the answers have to be rebuilt from scratch.

A small-office WISP typically runs 12-25 pages including policy snapshots and a control matrix.

Why it matters for Florida small business

Without a WISP your insurance review goes up; with one you can answer the standard renewal questionnaire in 10 minutes.

What to do

Adopt a WISP template, fill in your specifics, sign and date it, schedule annual reviews. Build one with your IT advisor, keep it current, and review it every year.

Related terms