What a written security plan looks like for a firm of twelve
Regulators increasingly expect a document, not a description. It does not need to be long — it needs to be true, current and specific to what you run.
There is a persistent belief that a written information security plan is a hundred-page artefact produced by a consultancy. For a firm of twelve people it is usually somewhere between eight and twenty pages, and the length is not what makes it credible.
What it has to contain
- What data you hold, where it lives, and who can reach it.
- A named person accountable for the program. Not a committee.
- The specific controls in place, described accurately enough to be checked.
- How you assess risk, how often, and what you did about the last assessment.
- How you handle an incident, including who is called and in what order.
- How vendors touching your data are selected and reviewed.
The failure mode
The common failure is not an absent plan. It is a plan that describes an organisation that does not exist — controls that were aspirational when written and never implemented. Under examination that is worse than having nothing, because it demonstrates that the document was never used.
Write the plan to match what you actually do, then improve both together. A modest, accurate plan with a tracked remediation list reads as a functioning program. A comprehensive, fictional one reads as a liability.
If you are a tax preparer, the IRS publishes a template in Publication 5708. It is a reasonable starting skeleton, but the content still has to be yours.