IRS Publication 5708 Explained: A Plain-English Guide for Tax Professionals
IRS Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice, is the official IRS guide for building your WISP. It was updated in August 2024 with new requirements around multi-factor authentication and breach reporting.
At 28 pages of government language, it's not exactly a page-turner. This guide translates the key points into plain English so you know exactly what the IRS expects.
What Is Publication 5708?
Publication 5708 is a sample WISP template created by the IRS Security Summit — a partnership between the IRS, state tax agencies, and the tax industry. It's designed to help tax professionals (especially smaller practices) develop their own Written Information Security Plan.
It's not a form you fill out and submit. It's a framework you use to build a plan customized to your practice.
You can download it directly from the IRS: Publication 5708 (PDF)
Who Is Pub 5708 Written For?
The publication is aimed at:
- Solo tax preparers
- Small to mid-size CPA firms
- Enrolled Agents
- Bookkeeping firms that handle client financial data
- EROs (Electronic Return Originators)
The IRS acknowledges that smaller practices have different needs than large firms. The template is designed to be scaled — a solo practitioner's WISP will be shorter than a 20-person firm's WISP.
What Publication 5708 Covers
The document walks through building a WISP in sections. Here's what each one requires:
Section 1: Getting Started — Security Coordinator
Every WISP must name a Qualified Individual (or Data Security Coordinator) responsible for your security program. For solo practitioners, that's you. For firms, it should be someone in leadership who can make security decisions and enforce policies.
What to document: Name, title, and responsibilities of your security coordinator.
Section 2: Risk Assessment
You must identify and assess risks to client data. This means looking at:
- Where is client data stored? (Computers, servers, cloud, paper files, email)
- Who has access to it? (Employees, contractors, software vendors)
- What could go wrong? (Theft, hacking, phishing, accidental exposure, natural disaster)
- How likely is each threat?
- What safeguards do you currently have?
What to document: A written risk assessment covering each area above, with identified gaps and plans to address them.
Section 3: Security Policies
This is the core of your WISP. You need written policies covering:
Password and Authentication:
- Minimum password requirements
- Multi-factor authentication (MFA) for all systems accessing client data
- The 2024 update to Pub 5708 now requires MFA unless your Qualified Individual has approved an equivalent control in writing
Data Protection:
- Encryption of client data at rest and in transit
- Secure file transfer methods
- Backup procedures
Physical Security:
- Locked offices, filing cabinets, and server rooms
- Visitor policies
- Clean desk practices
- Secure disposal of paper documents (shredding)
Remote Access:
- VPN requirements
- Policies for working from home
- Mobile device security
Access Control:
- Who can access what data
- Principle of least privilege (people only access what they need)
- Procedures for granting and revoking access
Section 4: Employee Training
All employees who handle client data must receive security training. This includes:
- Security awareness (phishing, social engineering, password hygiene)
- Your firm's specific policies and procedures
- What to do if they suspect a security incident
- Training for new hires before they access client data
- Refresher training at least annually
What to document: Training dates, topics covered, and acknowledgment signatures from each employee.
Section 5: Vendor and Service Provider Oversight
You must know who has access to your client data and ensure they protect it. This includes:
- Tax preparation software providers
- Cloud storage services
- IT support companies
- Document management systems
- Email providers
- Any contractor or outsourced service
What to document: A list of all vendors with access to client data, what data they access, and confirmation that they maintain adequate security measures.
Section 6: Incident Response Plan
Your WISP must include a plan for what happens when things go wrong:
- How to identify a security incident
- Steps to contain the damage
- Who to notify internally
- How to report to the IRS (contact your IRS Stakeholder Liaison)
- How to report to affected clients
- New in 2024: If 500+ people are affected, you must report to the FTC within 30 days
- How to report to state tax authorities
What to document: A step-by-step incident response procedure with contact information for all relevant parties.
Section 7: Annual Review
Your WISP is a living document. The IRS expects you to:
- Review your WISP at least once per year
- Update it when your business changes (new employees, new software, new office)
- Update it when new threats emerge
- Document each review with dates and any changes made
What Changed in the 2024 Update?
The August 2024 revision to Publication 5708 introduced two significant changes:
1. Multi-Factor Authentication Is Now Required
The previous version recommended MFA. The new version requires it for any individual accessing any information system containing client data. The only exception: your Qualified Individual can approve an alternative control in writing if they determine it provides equivalent or better security.
2. Breach Reporting to the FTC
If a security event affects 500 or more people, you must report it to the FTC within 30 days of discovery. This is in addition to notifying your IRS Stakeholder Liaison and state tax authorities.
Publication 5708 vs. Publication 4557
You may also see references to IRS Publication 4557 (Safeguarding Taxpayer Data). Here's the difference:
- Pub 4557 is a broader guide to data security for tax professionals. It covers best practices, checklists, and general security recommendations.
- Pub 5708 is specifically about creating your WISP. It provides the template and structure.
Think of Pub 4557 as the "what you should do" guide and Pub 5708 as the "how to document it" guide. You should be familiar with both.
Common Mistakes When Using Pub 5708
1. Copying the template word-for-word
The IRS sample is a starting point, not a finished product. Your WISP must be customized to your practice. A generic WISP that doesn't reflect your actual operations won't protect you during an audit.
2. Skipping the risk assessment
The risk assessment isn't optional padding. It's a core requirement of the FTC Safeguards Rule. Without a documented risk assessment, your WISP is incomplete.
3. Forgetting about vendors
Many tax professionals list their own security measures but forget to document their third-party vendors. If your tax software provider or cloud storage service has a breach, you need to show that you did your due diligence.
4. Creating it and forgetting it
A WISP that was written in 2022 and never updated is a compliance risk. Annual review is required, and your WISP should reflect your current operations.
5. No employee signatures
The FTC expects that employees have read and acknowledged your security plan. Unsigned policies are hard to enforce and harder to defend in an audit.
A Faster Path to Compliance
Publication 5708 gives you everything you need to build a WISP from scratch. But if you'd rather not spend days interpreting government language and writing policy sections, WISP Creator generates a complete, customized WISP from your answers to simple questions about your practice — addressing every section outlined in Pub 5708.
This article is for informational purposes and does not constitute legal advice. Always refer to the official IRS publications for the most current requirements.