Written Information Security Program (WISP)
Empire Elite Financial Solutions
Address: 2590 Oak Park Way, Orlando, FL 32822
Purpose
Empire Elite Financial Solutions is committed to protecting the confidentiality, integrity, and
security of sensitive information collected in the course of providing tax preparation, tax
planning, credit repair, and mentorship services. This WISP is designed to comply with the
Gramm-Leach-Bliley Act (GLBA), IRS Publication 4557, the FTC Safeguards Rule, and other
applicable regulations.
Scope
This WISP applies to all employees, contractors, and vendors of Empire Elite Financial
Solutions. It governs the security of both physical and digital data related to tax preparation, tax
planning, credit repair, and the mentorship program.
1. Data Collection and Classification
1.1 Types of Sensitive Information Collected
• Personal Identifiable Information (PII): Full name, Social Security Number (SSN),
date of birth, address, and driver’s license information.
• Financial Information: Tax returns, income statements (W-2s, 1099s), credit reports,
and payment details.
• Business Data: Financial forecasts and planning documents (for tax planning services).
• Mentorship Program Data: Personal and professional information of participants,
including contact details and goals.
All data collected is classified as Confidential and is protected under this WISP.
2. Security Controls
2.1 Physical Security
• Client files must be stored in locked filing cabinets when not in use.
• Office spaces must remain locked when unattended or outside business hours.
• All physical records must be shredded when no longer needed.
• Visitors must be escorted and are prohibited from accessing sensitive data.
2.2 Digital Security
• Sensitive information must be stored on encrypted devices or within secure cloud storage.
• Employees must use strong, unique passwords and multi-factor authentication (MFA).
• Install and update antivirus software and firewalls regularly.
• Use encrypted email or secure portals to transmit sensitive information electronically.
2.3 Access Control
• Access to sensitive information is limited to authorized personnel based on their job
responsibilities.
• Terminate access immediately upon an employee’s or contractor’s departure.
• Maintain individual user accounts to ensure accountability.
2.4 Data Retention
• Tax-related documents must be retained for a minimum of three years.
• Credit repair records must be retained for two years or as required by law.
• Mentorship program participant records must be securely deleted after the program
concludes unless otherwise agreed upon.
3. Risk Assessment
Empire Elite Financial Solutions conducts annual risk assessments to:
1. Identify vulnerabilities in systems or processes.
2. Evaluate the effectiveness of existing security measures.
3. Implement additional controls to mitigate identified risks.
4. Employee Training
All employees and contractors must complete annual training on:
• Recognizing and preventing phishing and social engineering attacks.
• Proper handling and storage of sensitive client information.
• Compliance with federal and state data protection regulations.
5. Incident Response Plan
5.1 Reporting and Containment
1. Notify the Compliance Officer immediately upon discovering a data breach or security
incident.
2. Contain the breach to prevent further unauthorized access.
5.2 Investigation and Notification
1. Assess the scope of the breach and identify affected clients.
2. Notify impacted clients, the IRS, and applicable regulatory authorities, as required.
5.3 Post-Incident Review
• Document the incident and implement corrective measures to prevent future breaches.
6. Vendor Oversight
Vendors with access to sensitive information must sign agreements ensuring compliance with
this WISP. Regular audits of vendor security practices will be conducted.
7. Program Maintenance and Review
This WISP will be reviewed and updated annually or after significant operational or regulatory
changes to ensure its effectiveness.
Compliance Officer: Darin Lyons
Effective Date: 11/24/24
Empire Elite Financial Solutions remains committed to safeguarding sensitive information and
ensuring client trust through compliance with this WISP.
24/7 Support
Lorem ipsum dolor sit amet, consectetur adipiscing elit
25 Years of experience
Lorem ipsum dolor sit amet, consectetur adipiscing elit
Service with love
Lorem ipsum dolor sit amet, consectetur adipiscing elit
Clients Focused
Lorem ipsum dolor sit amet, consectetur adipiscing elit
No policy fees
Lorem ipsum dolor sit amet, consectetur adipiscing elit
Growing your business
Lorem ipsum dolor sit amet, consectetur adipiscing elit
Frequently Asked Question
Lorem ipsum dolor sit amet, consectetur adipisicing elit. Autem dolore, alias, numquam enim ab voluptate id quam harum ducimus cupiditate similique quisquam et deserunt, recusandae.
Lorem ipsum dolor sit amet, consectetur adipisicing elit. Autem dolore, alias, numquam enim ab voluptate id quam harum ducimus cupiditate similique quisquam et deserunt, recusandae.
Lorem ipsum dolor sit amet, consectetur adipisicing elit. Autem dolore, alias, numquam enim ab voluptate id quam harum ducimus cupiditate similique quisquam et deserunt, recusandae.
Home | About Us | Employment | Upload Documents | Contact Us