Jump to content
ATX Community

Required Digital Security Plan - anyone willing to share?


BulldogTom

Recommended Posts

I use the form from AICPA slightly modified for my practice as a sole practitioner. I believe it largely mimics the one from IRS in Pub 4557.  It's hard as so much really doesn't seem to apply to the likes of me with a home office and no employees.  But my IT guy builds my system and internet protection (don't use wifi for the business computer) and works for several other small to medium sized local accounting and tax firms.  I also carry the additional network protection insurance through AICPA and have covered all their requirements.

Retirement looks better every single year!

  • Like 4
Link to comment
Share on other sites

4 hours ago, BulldogTom said:

Does anyone have a template version they would be willing to share?

This document was referenced on the the Tax Book forum as an excellent resource, published by the National Institute of Standards and Technology (NIST) of the U.S. Dept of Commerce and is available at https://doi.org/10.6028/NIST.IR.7621r1  as a 54-page pdf with a sample template in the appendix.

I usually don't share things from Drake, but this appears in my google search and appears to not be copyrighted. It is a template available to anyone searching the internet, and this link will launch a 20-page pdf directly from Drake's knowledge base: https://kb.drakesoftware.com/Attachment330.aspx .

Both of the links above will launch the pdfs directly, but if you are hesitant to click the links but are comfortable enough if I upload the pdfs here I can do that. Please know that I've clicked both links tonight on both my main desktop and my tablet, neither of which set off alarm bells with any of the three AV software products on either device.

 

  • Like 1
  • Thanks 2
Link to comment
Share on other sites

I used Kofax (formerly Nuance) to make the Drake form fillable. Unfortunately it skipped some areas and one page entirely, so I had to create some fields by hand, and they look a little rougher than the fields created automatically.

When enter the business name on page 1, it will link to all the other business name fields on the Acceptable Use Policy page. You might have to abbreviate the name for it to fit and be readable on the Acceptable Use Policy page.

Let me know if you find any bugs or changes you'd like to see.

Enjoy!

 

 

Tax Office Cyber Security Plan-Fillable.pdf

  • Like 2
Link to comment
Share on other sites

I've looked at Pub 4557, a security plan from BrassTax.com, one from Drake, and others. For my SMLLC home office with no employees but with a professional IT person who specializes in tax preparer and lawyer offices, I found the Pub 4557 Safeguarding Taxpayer Data's "Use the Safeguards Rule Checklist" of four pages (14-17 out of 21 pages) as a good starting point. However, I have not done anything else besides checking off the appropriate boxes in that checklist -- and having an IT pro on retainer and following his instructions.  

 

  • Like 2
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...