IRS Publication 5708 Explained: A Plain-English Guide for Tax Professionals

IRS Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice, is the official IRS guide for building your WISP. It was updated in August 2024 with new requirements around multi-factor authentication and breach reporting.

At 28 pages of government language, it's not exactly a page-turner. This guide translates the key points into plain English so you know exactly what the IRS expects.


What Is Publication 5708?

Publication 5708 is a sample WISP template created by the IRS Security Summit — a partnership between the IRS, state tax agencies, and the tax industry. It's designed to help tax professionals (especially smaller practices) develop their own Written Information Security Plan.

It's not a form you fill out and submit. It's a framework you use to build a plan customized to your practice.

You can download it directly from the IRS: Publication 5708 (PDF)


Who Is Pub 5708 Written For?

The publication is aimed at:

The IRS acknowledges that smaller practices have different needs than large firms. The template is designed to be scaled — a solo practitioner's WISP will be shorter than a 20-person firm's WISP.


What Publication 5708 Covers

The document walks through building a WISP in sections. Here's what each one requires:

Section 1: Getting Started — Security Coordinator

Every WISP must name a Qualified Individual (or Data Security Coordinator) responsible for your security program. For solo practitioners, that's you. For firms, it should be someone in leadership who can make security decisions and enforce policies.

What to document: Name, title, and responsibilities of your security coordinator.

Section 2: Risk Assessment

You must identify and assess risks to client data. This means looking at:

What to document: A written risk assessment covering each area above, with identified gaps and plans to address them.

Section 3: Security Policies

This is the core of your WISP. You need written policies covering:

Password and Authentication:

Data Protection:

Physical Security:

Remote Access:

Access Control:

Section 4: Employee Training

All employees who handle client data must receive security training. This includes:

What to document: Training dates, topics covered, and acknowledgment signatures from each employee.

Section 5: Vendor and Service Provider Oversight

You must know who has access to your client data and ensure they protect it. This includes:

What to document: A list of all vendors with access to client data, what data they access, and confirmation that they maintain adequate security measures.

Section 6: Incident Response Plan

Your WISP must include a plan for what happens when things go wrong:

What to document: A step-by-step incident response procedure with contact information for all relevant parties.

Section 7: Annual Review

Your WISP is a living document. The IRS expects you to:


What Changed in the 2024 Update?

The August 2024 revision to Publication 5708 introduced two significant changes:

1. Multi-Factor Authentication Is Now Required

The previous version recommended MFA. The new version requires it for any individual accessing any information system containing client data. The only exception: your Qualified Individual can approve an alternative control in writing if they determine it provides equivalent or better security.

2. Breach Reporting to the FTC

If a security event affects 500 or more people, you must report it to the FTC within 30 days of discovery. This is in addition to notifying your IRS Stakeholder Liaison and state tax authorities.


Publication 5708 vs. Publication 4557

You may also see references to IRS Publication 4557 (Safeguarding Taxpayer Data). Here's the difference:

Think of Pub 4557 as the "what you should do" guide and Pub 5708 as the "how to document it" guide. You should be familiar with both.


Common Mistakes When Using Pub 5708

1. Copying the template word-for-word

The IRS sample is a starting point, not a finished product. Your WISP must be customized to your practice. A generic WISP that doesn't reflect your actual operations won't protect you during an audit.

2. Skipping the risk assessment

The risk assessment isn't optional padding. It's a core requirement of the FTC Safeguards Rule. Without a documented risk assessment, your WISP is incomplete.

3. Forgetting about vendors

Many tax professionals list their own security measures but forget to document their third-party vendors. If your tax software provider or cloud storage service has a breach, you need to show that you did your due diligence.

4. Creating it and forgetting it

A WISP that was written in 2022 and never updated is a compliance risk. Annual review is required, and your WISP should reflect your current operations.

5. No employee signatures

The FTC expects that employees have read and acknowledged your security plan. Unsigned policies are hard to enforce and harder to defend in an audit.


A Faster Path to Compliance

Publication 5708 gives you everything you need to build a WISP from scratch. But if you'd rather not spend days interpreting government language and writing policy sections, WISP Creator generates a complete, customized WISP from your answers to simple questions about your practice — addressing every section outlined in Pub 5708.

Build your WISP in minutes →


This article is for informational purposes and does not constitute legal advice. Always refer to the official IRS publications for the most current requirements.