Skip to main content

WISP Review & Update Process

Review and update your WISP annually or whenever there is a significant change to your business that could affect information security.

Updated over a month ago

Time for Your Annual WISP Review!

Now is the perfect time to make sure your Written Information Security Plan (WISP) is up to date and reflects your organization’s current practices. Keeping your WISP current isn’t just good security hygiene—it’s a regulatory and risk management must.

Step 1: Review Your Current WISP

Take a few minutes to review your existing WISP. Has your business changed in the past year? Maybe you’ve added new systems, updated vendors, or shifted how employees work. These changes can affect your security procedures and need to be reflected in your documentation.

Step 2: Create a New WISP from Your Current WISP

Inside WISP Builder it’s easy to start your annual update:

  1. Click Build My WISP (this is in the top bar of all the WISP tabs)

  2. When prompted, select Use my active WISP as a template

  3. Click Get Started

  4. This ensures you keep all your existing content and settings while starting with a clean, updated version for the new year or after any significant business changes

Step 3: Make Updates and Revisions

Scroll and review each section carefully and make any necessary updates:

  1. Revise employee roles or responsibilities, you will need to select each role again

  2. Review and update information for inside and outside the firm

  3. Update Policies

  4. Add any new attachments

  5. Once on the Finalize tab, click the Review Required button

  6. Review your WISP

  7. After your Review, click This is correct, to move on to next step, if you need to make changes, click Make a change

  8. Once you have selected "This is correct", you can click on the button to Finalize and Send for Signatures

1. Example - Select roles

2. Example - Review (Required)

3. Example - Review your WISP and click through all pages in your WISP. Total number of pages will be different for all companies based in custom input.

4. Example - Once you have reviewed all pages for accuracy, click This is Correct or you can choose to make changes

5. Example - click on Finalize and Send for Signatures

Step 4: WISP Builder will automatically send emails for review and signatures

The emails will be sent from WISP Builder to the individuals you assigned during the WISP creation process. These emails will have a subject line as "A Pending WISP needs your Signature"

  • Once these role holders have acknowledged and signed, your WISP will then become Active.

  • This step helps ensure everyone is informed and accountable for protecting sensitive information.

Why It Matters

Keeping your WISP current ensures your organization stays compliant, reduces legal and operational risks, and shows your commitment to safeguarding customer and employee data.

Did this answer your question?