SYNTHETIC TEST DOCUMENT — FICTIONAL COMPANY — NO CUSTOMER DATA Cedar Hollow Tax Services LLC Written Information Security Plan (WISP) Document ID: CHT-SEC-001 | Version 2.0 | Effective: 2026-09-01 Owner: Qualified Individual, Security Lead | Approved by: Managing Partners 1. Purpose and scope Cedar Hollow is a fictional tax preparer and electronic return originator. This information security program covers taxpayer data, tax return information, client portal records, paper files, laptops, cloud services, and vendors that handle customer information. The Security Lead maintains a system and data inventory and reviews this WISP every year and after material changes. 2. Risk assessment SOP Each January, the Security Lead documents reasonably foreseeable internal and external risks, assesses likelihood and impact, identifies controls, and records residual risk in the risk register. New software, vendors, or workflows require a risk review before launch. Managing Partners approve any risk exception, with an owner and expiration date. 3. Access control SOP Only named accounts may access customer information. The Operations Manager approves access based on job need and least privilege. The Security Lead reviews access rights quarterly; managers report role changes within one business day. IT disables departing staff accounts on their departure date. Shared accounts are prohibited. 4. Authentication, encryption, and device rules Multi-factor authentication is required for all staff access to the client portal, email, remote access, and systems containing customer information. Customer information is encrypted at rest on managed laptops and servers and encrypted in transit with TLS. IT records encryption exceptions, applies compensating controls, and obtains written approval from the Security Lead before use. Unmanaged devices may not store taxpayer data. 5. Training and testing SOP Employees complete security awareness training at hire and annually. The Security Lead performs quarterly phishing exercises and documents follow-up coaching. Vulnerability scans run monthly; a qualified independent tester performs an annual penetration test. The Security Lead tracks findings to closure and verifies fixes. 6. Vendor oversight SOP Before a service provider receives customer information, Procurement documents due diligence on its safeguards and incident response. Contracts require appropriate security controls and prompt incident notice. The Security Lead reviews critical providers annually and records remediation for material gaps. 7. Incident response SOP Staff report suspected unauthorized access immediately to the Security Lead. The incident response team preserves evidence, contains affected accounts, assesses what customer information was involved, coordinates recovery, and records decisions in an incident log. Legal counsel determines any applicable customer or regulator notice obligations. The team conducts a lessons-learned review within 30 days of closure. 8. Retention and secure disposal SOP The Records Manager keeps a retention schedule by record type and documents legal holds. When retention expires, paper containing customer information is cross-cut shredded by an approved vendor; electronic copies are securely erased or destroyed. Vendor destruction certificates are retained. Exceptions require a documented legal or business reason and a review date. Backups follow the approved deletion schedule. 9. Governance and evidence The Security Lead gives the Managing Partners a written annual report covering risk assessment results, control testing, security events, vendor status, and recommended changes. Evidence records include access reviews, training logs, scan results, incident logs, disposal certificates, and approval minutes. TEST INTENT: A relatively detailed WISP with named owners, actions, timing, and evidence. It is a synthetic fixture, not proof that any real company follows these steps.