Deziel's Tax Service · Website and security plan
Mark Deziel · Mike Deziel · Joe Skelley
Three items. Tap a heading to open it.
The privacy statement is the page on the website that tells your clients what you collect and what you do with it. Anyone can read it. It is a public promise.
The security plan — the WISP, or Written Information Security Plan — is an internal document. The IRS requires it of any paid preparer filing eleven or more federal returns a year, and the FTC Safeguards Rule requires it because a paid tax preparer counts as a financial institution under federal law. Nobody outside the office reads it unless something goes wrong or someone asks: an insurer, an auditor, or the IRS after an incident.
They have to agree with each other. The public page must not claim a protection the office doesn't actually perform.
The plan is drafted in full. It covers all nine elements the FTC Safeguards Rule requires, it has a complete incident-response attachment with the reporting contacts already researched, and it has a risk worksheet with nine risks laid out.
Outstanding: the facts in the worksheet below, and three items to close — sign the data-handling agreement between Deziel's and Joe's Tech Support, name the security coordinator, and confirm the database platform's service tier.
The security plan working draft — the file deziel-wisp.md in Joe's Deziel folder.
The current privacy statement — the Privacy Policy page on the rebuilt site
dts-rebuild.pages.dev/privacy
1. Effective date of the plan
The date it is adopted, and today's date as the first review.
2. Security coordinator
One named person accountable for the plan. Name, title, phone and email.
3. Systems inventory — where client information lives and who can reach it
For each one: where it sits, and the list of people with access.
Tax preparation software (Drake today)
Installed on the office machines, or hosted?
Office computers and workstations
Google Workspace Business Starter, one licensed mailbox. Other addresses are aliases or groups — which, and who reads each one.
File storage and document exchange
Website and client login
Paper files
4. Under five thousand client records?
Below that count, the annual written report to ownership eases. Every other control applies either way.
5. Anti-malware product
Which one, and on which machines.
6. Backups
Method, frequency, and where the copies live.
7. Physical security of the office
Locked storage for paper, the office secured when unattended, alarm, cameras, who holds keys.
8. How long records are kept
The retention period before paper is shredded and electronic files are deleted.
9. Training used
What staff get on phishing and handling client documents, at hiring and once a year after.
10. How acknowledgment is recorded
A signed sheet, an email, a line in a personnel file.
11. Cyber-insurance carrier
Carrier, policy number, claims phone line.
12. The risk worksheet ratings
Nine risks with a starting likelihood and impact — phishing, ransomware, a lost laptop, paper left out, a departing employee, and the rest. Each needs a confirmation or an adjustment.
The current site — reference for what was there
dezielstaxservice.com
The new site — current status
dts-rebuild.pages.dev
The site's buttons go to the office phone number today.