WISP writing.

A Written Information Security Program (WISP) and supporting policies tailored to your data, systems, and responsibilities. We draft the documents, review them with leadership and IT, and define how they will be adopted and maintained.

  • 1–2 weeksTypical drafting timeline
  • Plain languageReadable by leadership, usable by IT
  • YoursBuilt from how your business runs, not a template dump
  • One advisorStart to finish

When to use this service.

01

Document your security program

Use this service when your organization needs a written program for customer requirements, insurance requests, or an applicable regulatory obligation.

02

Replace inaccurate policies

Policies should describe approved responsibilities and safeguards. We identify where existing documents do not match your operations and separate current practices from planned improvements.

03

Assign policy owners

A policy set needs approval, responsible owners, staff communication, and review dates. These are addressed during the drafting and adoption process.

Best fit: Organizations needing a new WISP, an update to outdated policies, or documentation for a customer, insurer, or applicable regulatory requirement.

Outside this service: A request for legal advice, certification, or implementation of every technical safeguard. A broader ISMS or implementation project requires a separate scope.

What a WISP is.

Program document

The WISP defines the information covered, program responsibilities, risk-management approach, and administrative, technical, and physical safeguards.

Supporting policies

The agreed policy set covers topics such as access control, MFA, acceptable use, data handling, vendor oversight, and incident response.

Applicable requirements

Covered financial institutions under FTC jurisdiction must maintain a written information security program. Applicability depends on activities and jurisdiction, not simply a company's industry label.

Our process.

The engagement covers drafting, stakeholder review, approval support, and document maintenance responsibilities.

  1. Step 01

    Confirm the policy scope

    Review your current documents, data, operations, and requested requirements. Agree the policy list, review rounds, responsibilities, and fee in writing.

  2. Step 02

    Draft the program and policies

    Interview system and business owners, then prepare the WISP and agreed policies. Initial drafting typically takes one to two weeks, depending on scope and available information.

  3. Step 03

    Review with leadership and IT

    Check responsibilities, control descriptions, and implementation needs. Planned safeguards are identified as actions rather than described as already operating.

  4. Step 04

    Approve and maintain the documents

    Deliver the final versions, document owners, approval record, and review schedule. Your organization approves the policies and implements the required safeguards.

Why Hardenwell.

A dedicated advisor

A named, CISSP-certified advisor leads your engagement, with specialist support where needed. Responsibilities and the agreed deliverables are documented before work begins.

No referral commissions

We do not receive referral commissions from auditors, testing firms, brokers, or software vendors. External services are identified separately so you can review their scope and fees.

Documents your team owns

You receive the agreed WISP, policy set, approval responsibilities, and review schedule. Technical implementation is distinguished from policy drafting.

Client reviews.

MB2 Dental

The biggest win was getting a clearer standard, a practical first set of fixes, and a way for our IT team to move without waiting on endless internal debate.
Rick V.Vice President, Information Technology

PDS Health / Pacific Dental Services

We were not looking for a cookie-cutter security review. The consulting team at Hardenwell took time to understand how our technology environment supports the business, then gave us recommendations that were practical, sequenced, and specific enough to act on.
David B.Chief Information and Digital Officer

Grassi

The technical findings mattered, but the bigger value was how the Hardenwell advisor explained them. They translated security risk into business risk for our partners, then worked with IT on the details. Decisions moved faster because both sides understood the same issue.
Kenny L.Chief Information Officer

Frequently asked questions.

Book your scope call.

Thirty minutes with an advisor.

We cover your organization, your deadline, and who is asking for what. You leave knowing the likely scope, the timeline, and your next step, with the price fixed in writing before any work starts.

Prefer phone or email?

(754) 216-9664 [email protected]

Do not include PHI or sensitive records in booking notes. See our Privacy Policy.

Book a call