GLBA WISP Requirements: Building a Written Information Security Program
The Gramm-Leach-Bliley Act’s Safeguards Rule requires every covered financial institution to develop, implement, and maintain a Written Information Security Program — a WISP — that is appropriate to the organization’s size, complexity, and the sensitivity of the customer information it handles. A policy binder is not a WISP. A WISP is an operational program with documented controls, tested procedures, assigned accountability, and evidence that it functions continuously. Armorstack builds and governs GLBA WISPs for regulated financial institutions across the mid-market.
What a GLBA WISP Must Contain
The FTC’s updated Safeguards Rule specifies the elements a written information security program must address. These are not aspirational guidelines — they are required program components. An organization that cannot produce documentation for each element is not in compliance, regardless of whether its actual security controls are strong.
Risk Assessment Documentation
The WISP must be grounded in a written risk assessment that identifies foreseeable internal and external risks to customer information and evaluates the sufficiency of current safeguards. The assessment must be conducted at program inception, updated when material changes occur, and reviewed at least annually. The risk assessment is the foundation on which every other WISP element rests — controls that are not tied to an identified risk are difficult to defend, and risks that are identified but not addressed are explicit compliance gaps.
Safeguard Policies and Procedures
The WISP must document policies and procedures for each of the required safeguards: access controls, data inventory and classification, encryption at rest and in transit, secure development practices, authentication requirements including multifactor authentication, data disposal, change management, and monitoring and testing. Each policy must be implemented — not merely written. The FTC distinguishes between organizations that have controls on paper and organizations that have controls in operation.
Designation of a Qualified Individual
The WISP must identify the individual responsible for overseeing and implementing the program. This person — the Qualified Individual — may be an employee or a service provider. Their name or role must appear in the WISP, and the program must describe how they fulfill the oversight function, including the process for their required annual report to the board. Review the GLBA Qualified Individual requirement for a detailed analysis of how this role is structured and fulfilled, including when an outside provider is used.
Service Provider Management
The WISP must address how the organization selects, oversees, and contracts with service providers that have access to customer information. This includes the criteria for service provider selection, the contractual requirements imposed on service providers, and the ongoing oversight process. Service provider management is one of the most consistently cited gaps in FTC examinations — organizations frequently have vendor lists but lack the contractual safeguard requirements the rule mandates.
Testing and Monitoring Procedures
The WISP must describe the testing and monitoring program. For organizations with 5,000 or more customer records, this includes annual penetration testing and semi-annual vulnerability assessments. For smaller organizations, testing must be continuous or periodic and appropriate to the risk environment. The WISP must document how test results are reviewed, how identified vulnerabilities are remediated, and how remediation is verified. Armorstack’s managed detection and response provides the continuous monitoring layer that satisfies the ongoing monitoring requirement.
Incident Response Plan
The WISP must include or incorporate by reference a written incident response plan. The FTC’s requirements for the plan include: defined goals, internal response processes, roles and responsibilities, internal and external communication requirements including FTC notification for qualifying events, a process for remediation, and a post-incident review process. The plan must name the individuals or roles responsible for each function — it cannot be written as if response will be improvised.
Annual Board Report
The WISP must describe the process by which the Qualified Individual reports to the board of directors or equivalent governing body at least annually. The report itself must cover the status of the information security program, risk assessment results, risk management decisions, service provider arrangements, test results, security events, and recommendations for program changes. The WISP should specify the format, frequency, and distribution of this report so it functions as a repeatable process rather than an ad hoc briefing.
Common WISP Gaps the FTC Finds
FTC enforcement patterns reveal consistent weaknesses in how mid-market financial institutions approach WISP development. The most frequent gaps are not exotic — they are structural omissions that result from treating the WISP as a documentation project rather than an operational program.
Risk assessments exist as standalone documents with no connection to the controls the organization actually implemented. Service provider provisions are absent from vendor contracts despite the organization having dozens of vendors with access to customer data. Incident response plans name functions rather than people, so when an incident occurs no one has clear authority. Testing documentation shows penetration tests were conducted but remediation findings are untracked. Board reports were delivered verbally and not documented, leaving no evidence they occurred.
Each of these gaps is individually citable as a Safeguards Rule violation. Collectively, they indicate that the WISP exists on paper but not in operation — the distinction the FTC cares most about.
WISP vs. Policy: The Operational Difference
A policy document states what an organization intends to do. A WISP is the documentation that an organization is doing it — and the system that ensures it continues to happen. The difference is operational continuity: a WISP includes procedures, not just policies; it assigns owners, not just responsibilities; it defines what evidence is produced and retained; and it establishes the update cadence that keeps the program current as the business and threat environment evolve.
Armorstack’s VERITY advisory team builds WISPs that are designed to operate, not just to pass a review. The program framework connects to SENTRY’s monitoring telemetry for continuous evidence production, to CORE’s infrastructure controls for technical safeguard documentation, and to the Qualified Individual function for governance accountability. Learn more about the full GLBA Safeguards Rule requirements and how the WISP fits within the nine required program elements. Return to the GLBA compliance hub for the complete framework overview.
Getting Your WISP Built and Verified
Armorstack’s 90-Day Proof engagement is structured to produce a complete, FTC-defensible WISP within the initial engagement window. The process begins with a gap assessment against all required program elements, progresses through policy and procedure development, control implementation verification, and Qualified Individual designation, and concludes with a board-ready program package including the first annual report template. Every element is documented, assigned, and connected to an operational control — not left as a policy statement awaiting future implementation. See all compliance frameworks Armorstack supports for regulated mid-market organizations. Start the 90-Day Proof →
Frequently Asked Questions
What is a GLBA WISP and who needs one?
A GLBA WISP is a Written Information Security Program required by the FTC Safeguards Rule for non-bank financial institutions subject to FTC jurisdiction. It must document the organization’s risk assessment, safeguard controls, service provider management, testing and monitoring procedures, incident response plan, and the process for annual board reporting by the Qualified Individual.
How often must a GLBA WISP be updated?
The Safeguards Rule requires the information security program to be reviewed and adjusted in response to material changes in operations or business arrangements, changes in the threat landscape, and results from testing and monitoring. The underlying risk assessment must be updated when material changes occur and reviewed at a minimum annually. There is no fixed update schedule — the program must remain current, which requires an ongoing review process.
Can a service provider fulfill the WISP obligations on behalf of a financial institution?
A service provider can fulfill the Qualified Individual role and can build and operate the information security program on behalf of a covered financial institution. However, the financial institution retains legal accountability for the program. The institution must maintain oversight of the service provider’s activities and the program must still meet all required elements under the Safeguards Rule.
What is the difference between a GLBA WISP and an incident response plan?
A GLBA WISP is the overarching written information security program that encompasses all required safeguard elements, including the risk assessment, safeguard policies, service provider management, and board reporting process. An incident response plan is one required component within the WISP. The Safeguards Rule requires both, and the incident response plan must be written and must address specific elements including roles, communication protocols, remediation processes, and post-incident review.