• Home
  • 5
  • Insights
  • 5
  • Create an Effective Information Security Program
Create an Effective Information Security Program

Create an Effective Information Security Program

by Michael Nouguier | Jun 14, 2023

All SEC-Registered funds are required to have an information security program in place, but where does one start when creating the various policies and procedures a fund may need? A Written Information Security Program, known as a WISP, is the best place to start. A WISP document is a comprehensive written plan that outlines an organization’s approach to information security. It serves as a blueprint or roadmap for managing and protecting sensitive information within an organization. After you determine what areas you need to secure, the next step is to plan the how. What a WISP doesn’t lay out is the HOW, that needs to be defined in separate policy and procedure documents thereafter. More on that later.

Your WISP should be your foundation to define how the organization is going to secure sensitive and confidential information. There are many areas that fund may be required to create policies and procedures for, but the most common include access control, data encryption, and vendor management for example.

The cybersecurity experts at Richey May have created a WISP template funds can reference to begin creating a WISP in accordance with industry standards and best practices.

Please note that you will need to allow pop-ups in order for the download to open after filling out the below form.

 

 

 

Explore More Insights

  • There are no suggestions because the search field is empty.

Some of these items predate Richey May’s restructuring to an alternative practice structure. Richey May is no longer a CPA firm. All Attest services are provided by Richey, May & Co., LLP.

Our Latest Insights

Looking for more industry expertise and to stay up to date? Check out more from the experts at Richey May below:

When Geopolitics Goes Digital: What Iranian Cyber Activity Means for Businesses

A wise wizard’s job is to warn people before things go wrong. Staying alert before the danger...

When Nobody Owns the Problem: IT/OT Convergence Failures at U.S. Utilities

Nation-state actors are exploiting the organizational gap between IT and OT security teams. For...

Lessons from Unanticipated OT and IoT Vulnerabilities at Major Airports

August 24, 2024. Saturday morning at a major international airport in the Pacific Northwest....

Freddie Mac’s Updated Cybersecurity Requirements: January 1, 2026 effective

As of January 1, 2026, Freddie Mac’s enhanced information security requirements are now in effect,...