[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-143469-en":3,"doc-seo-143469-105":30,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},143469,962075114101,"Seraphina","https://ap-avatar.wpscdn.com/avatar/e000253a75eb197efd?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780044092746381165",6,"Technology","Why Your Small Business Needs an Information Security Policy and a WISP","Explains the role of an information security policy and why small businesses should adopt a Written Information Security Program (WISP). Clarifies how a general information security policy sets an organization’s commitment, while more specific policies (e.g., risk management, virus protection) sit beneath it. Defines WISP as the full package of policies plus the implementation program, including training and ongoing management review. Emphasizes practical business value for compliance and risk reduction.","TECH BRIEF Why your small business needs an information security  \npolicy and a WISP  \nTech Brief  \nWHY YOUR SMALL BUSINESS NEEDS AN INFORMATION SECURITY POLICY AND A WISP  \nBy Stephen Cobb, ESET Security Researcher  \nA recent question about need cases for singular versus multiple policies got me thinking about how information security people talk about policy—and I realized it can be confusing. So here are some explanations about security, policies and a thing called WISP.  \nFirst of all, what does it mean for an organization to have an information security policy, singular? It means that the organization has stated and recorded its commitment to protecting the information that it handles. For example, here is what Acme Bicycle Company might say:  \nIt is the policy of ABC that information, as defined hereinafter, in all its forms—written, spoken, recorded electronically, or printed—will be protected from accidental or intentional unauthorized modification, destruction, or disclosure throughout its life cycle. This protection includes an appropriate level of security over the equipment and software used to process, store, and transmit that information.  \nThis statement of overall policy usually appears as the preamble to a series of more specific policies. For example, there may be a section on risk management:  \nA thorough analysis of all ABC information networksand systems will be conducted on a periodic basis to  \ndocument the threats and vulnerabilities to stored and transmitted information.  \nThere should probably be a virus protection policy. It that might say something like this:  \nVirus checking systems approved by the information security officer and Information Services must be deployed using a multi-layered approach (desktops, servers, gateways, etc.) that ensures that all electronic files are appropriately scanned for viruses. Users are not authorized to turn off or disable virus checking systems.  \nSo there are multiple specific policies below the overall information security policy. There is another term you may see in this context: written information security program or WISP (not to be confused with Wireless Internet Service Provider) .  \nWISP is a term that encompasses all relevant policies plus your organization’s program for implementing them. I like the term because it implies something more practical that just a collection of policies sitting in a binder (although the WISP will likely sit in a binder too) . Regular readers may recall that WISP plays a prominent role in some information security legislation, notably the law in Massachusetts, which says:  \nEvery person that owns or licenses personal information about a resident of the Commonwealth shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards…  \n1  \nTech Brief  \nI won’t go into the details about Massachusetts law, since the main points were covered in the earlier article1 , but suffice it to say I think that every business, large or small, needs to have aWISP. This may simply be an attachment to existing policies that says:  \nThe ABC Written Information Security Program consists of the enclosed policies and the steps we take to enforce them, including dissemination of polices to all new employees and the regular training of all employees on how to uphold the policies in their work, together with a periodic management review of the program to ensure that all aspects of information security in our organization are appropriately addressed at all times.  \nIf you meet resistance when it comes to the not-inconsiderable effort of creating and executing aWISP, try persuading skeptics with a litany of examples of small firms that actually went out of business or suffered severe loss because of cyber criminals, many of whom could have been defeated if the victim had been on top of the problem. Where to find the f","cbCaibN2qFvPE5W4","https://ap.wps.com/l/cbCaibN2qFvPE5W4","pdf",708774,1,4,"English","en",105,"# Introduction\n## What an information security policy means\n## From policies to a WISP\n# Why a WISP matters for small businesses\n## Examples and compliance requirements\n## Vendor due diligence and contracts","[{\"question\":\"What is the purpose of having an information security policy (singular) in an organization?\",\"answer\":\"It states and records the organization’s commitment to protecting the information it handles. It also describes an appropriate level of security for the equipment and software used to process, store, and transmit the information.\"},{\"question\":\"How is a WISP different from simply having multiple security policies?\",\"answer\":\"A WISP encompasses all relevant policies plus the organization’s program for implementing them. It focuses on practical execution, not just policies kept in a binder.\"},{\"question\":\"Why does the document argue that small businesses need a WISP?\",\"answer\":\"A WISP helps defeat cyber criminals and supports timely compliance. It also enables smaller firms to meet vendor contract requirements and reduce the risk of losing business to competitors with documented security programs.\"}]","Why Your Small Business Needs an Information Security Policy and a WISP | PDF",1787695280,10,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":28},"why-your-small-business-needs-an-information-security-policy-and-a-wisp","",{"@graph":36,"@context":84},[37,53,67],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":21},"https://docshare.wps.com/document/why-your-small-business-needs-an-information-security-policy-and-a-wisp/143469/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-08-25",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What is the purpose of having an information security policy (singular) in an organization?","Question",{"text":74,"@type":75},"It states and records the organization’s commitment to protecting the information it handles. It also describes an appropriate level of security for the equipment and software used to process, store, and transmit the information.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How is a WISP different from simply having multiple security policies?",{"text":79,"@type":75},"A WISP encompasses all relevant policies plus the organization’s program for implementing them. It focuses on practical execution, not just policies kept in a binder.",{"name":81,"@type":72,"acceptedAnswer":82},"Why does the document argue that small businesses need a WISP?",{"text":83,"@type":75},"A WISP helps defeat cyber criminals and supports timely compliance. It also enables smaller firms to meet vendor contract requirements and reduce the risk of losing business to competitors with documented security programs.","https://schema.org",{"og:url":52,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,112,117,122,127,130,133],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":110,"slug":111},50,"technology",{"id":113,"doc_module":4,"doc_module_name":46,"category_name":114,"show_sort_weight":115,"slug":116},7,"Healthcare",40,"healthcare",{"id":118,"doc_module":4,"doc_module_name":46,"category_name":119,"show_sort_weight":120,"slug":121},8,"Research & Report",30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":29,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":29,"slug":132},"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":105,"slug":136},19,"General","general"]