Document Control
Status: Operational policy template pending final approval by company leadership, counsel, and the designated security professional. This plan must be implemented in practice; publication alone does not establish compliance.
1. Purpose and Scope
Luna Lux Financial maintains this WISP to protect personally identifiable information and nonpublic personal information handled in paper, electronic, or other form. It applies to owners, employees, contractors, tax preparers, trainees, interns, vendors, devices, networks, cloud services, offices, and remote-work locations that access Firm information.
The program is designed to preserve confidentiality, integrity, and availability; reduce foreseeable risks; prevent unauthorized access; and support applicable obligations under the Gramm-Leach-Bliley Act, FTC Privacy and Safeguards Rules, IRS guidance, tax law, contracts, and applicable state law.
2. Information Covered
- Names, addresses, dates of birth, Social Security and taxpayer identification numbers.
- Tax returns, income records, bank information, identity documents, dependent information, signatures, IP PINs, e-file credentials, and client communications.
- Applicant and workforce records, background information, payroll, access credentials, and training records.
- Any combination of data that could identify, authenticate, profile, or financially harm a person or business.
Data is classified as Restricted (taxpayer records, credentials, government IDs), Confidential (applicant, workforce, financial, and internal business records), Internal, or Public. Restricted and Confidential information receive the strongest controls.
3. Roles and Accountability
- WISP Coordinator / Qualified Individual: leads risk assessment, safeguards, testing, incidents, vendor oversight, training, and annual reporting.
- Leadership: approves resources, receives material-risk reports, enforces the plan, and documents exceptions.
- Supervisors: approve access based on job need and promptly report role changes.
- All workforce members: complete training, use approved systems, safeguard credentials, and immediately report suspected incidents.
No new preparer receives production-system or taxpayer-data access until identity verification, agreements, security training, and role-based authorization are complete.
4. Risk Assessment
The Firm maintains a written, periodically updated inventory of data, devices, applications, service providers, users, collection points, storage locations, transmissions, and disposal methods. The WISP Coordinator evaluates likelihood and impact of threats including phishing, credential theft, malware, ransomware, lost devices, insider misuse, insecure remote work, excessive privileges, vendor failure, physical theft, improper disposal, and business interruption.
Each material risk receives an owner, safeguard, target date, residual-risk rating, and documented acceptance or remediation decision.
5. Administrative Safeguards
- Access is least-privilege, role-based, manager-approved, reviewed at least quarterly during filing season, and removed immediately upon separation or loss of need.
- Unique accounts are required; shared credentials are prohibited. Access acknowledgments and confidentiality agreements are retained.
- Security-awareness training occurs before access and at least annually, with filing-season refreshers and phishing/social-engineering guidance.
- Only the minimum information necessary is collected, used, shared, and retained.
- Taxpayer documents may be exchanged only through approved secure portals or other authorized encrypted methods—not personal email, consumer messaging apps, or personal cloud drives.
- Service providers are risk-assessed, contractually required to safeguard information, periodically monitored, and removed when no longer needed.
- Material system, workflow, vendor, or staffing changes receive security review before implementation.
6. Technical Safeguards
| Control | Minimum Standard |
|---|---|
| Authentication | Multi-factor authentication for systems containing customer information; strong unique passwords stored in an approved password manager. |
| Encryption | Restricted data encrypted in transit and at rest, or an equivalent written control approved by the WISP Coordinator where encryption is not feasible. |
| Devices | Firm-approved, inventoried devices; screen lock; supported operating systems; timely patches; firewall; anti-malware/endpoint protection; no unapproved USB storage. |
| Networks | No taxpayer-data access over public or unsecured Wi-Fi without an approved protected connection. Default router credentials must be changed. |
| Monitoring | Log and review authorized-user activity and security alerts; investigate anomalies and unauthorized-access attempts. |
| Backups | Encrypted, access-controlled backups tested for restoration; business-continuity procedures documented. |
| Testing | Safeguards are monitored and tested at a frequency appropriate to risk and applicable rule requirements, with remediation tracked. |
7. Physical and Remote-Work Safeguards
- Clean-desk and clear-screen practices; paper containing sensitive data is locked when unattended.
- Visitors are controlled in work areas. Printed tax records are minimized and securely shredded using an approved service.
- Devices are never left unattended in vehicles or public places and must be stored securely.
- Remote preparers use a private workspace, prevent household or public viewing, disable voice assistants near taxpayer discussions, and use headsets for confidential calls.
- Printing at home requires written approval and secure storage/disposal.
8. Incident Response
- Report immediately: Contact the WISP Coordinator for suspected phishing, misdirected data, lost devices, unusual login prompts, malware, or unauthorized access. Do not conceal, investigate independently, or delete evidence.
- Contain: Disconnect affected equipment from networks when safe; preserve logs and communications; do not power off unless directed.
- Assess and eradicate: Identify systems, people, data, dates, attack path, and ongoing risk; engage approved technical and legal resources.
- Recover: Restore from trusted sources, reset credentials, increase monitoring, validate security, and document decisions.
- Notify: Leadership determines required notices to the FTC, IRS, state tax agencies, law enforcement, insurers, affected persons, or others based on verified facts and applicable law.
- Improve: Complete a documented post-incident review and update safeguards, training, risk assessment, and this WISP.
9. Retention and Secure Disposal
The Firm maintains a documented retention schedule based on legal, contractual, operational, and defense needs. Customer information is securely disposed of when no longer required, subject to applicable exceptions. Electronic data is securely erased or media destroyed; paper is cross-cut shredded or handled by an approved destruction vendor. Disposal is logged when appropriate.
10. Training, Enforcement, and Acknowledgment
Training records and signed acknowledgments are retained. Violations may result in removal of access, corrective action, termination of engagement, and referral to authorities where appropriate. Exceptions require a written business justification, risk review, compensating controls, approval by the WISP Coordinator, and an expiration date.
11. Review and Maintenance
The WISP Coordinator reviews this plan at least annually and after material operational changes, test findings, new threats, or security events. Each review records decisions, unresolved risks, responsible owners, and deadlines. Leadership receives a written status report appropriate to the Firm’s size and obligations.
Workforce Acknowledgment
I acknowledge that I have received, read, and understand the Luna Lux Financial WISP. I agree to comply with all security procedures, use only approved systems, protect credentials, report suspected incidents immediately, complete assigned training, and return or destroy Firm information when directed.
Name: ____________________ Signature: ____________________ Date: __________