| name | wisp |
| title | Written Information Security Program (WISP) |
| description | Drafts a Written Information Security Program compliant with Massachusetts 201 CMR 17.00 and supplementary frameworks (GDPR, CCPA, HIPAA, GLBA, PCI-DSS). Produces a board-ready regulatory document covering coordinator designation, risk assessment, safeguards, training, incident response with breach notification, and vendor oversight. Use when an organization handles personal information of MA residents and needs a standalone WISP for regulatory examination or executive approval. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/wisp |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | cybersecurity |
| language | en |
| tags | ["drafting","memo","regulatory","research"] |
Written Information Security Program (WISP)
Drafts a 201 CMR 17.00-compliant WISP that satisfies regulatory examination and functions as an operational security blueprint.
Prerequisites
- Organization profile — legal name, industry, jurisdictions, employee count
- Data inventory — PI types, storage locations, transmission methods, access roles
- Existing security materials — current policies, prior WISPs, risk assessments, audit reports, incident logs
- Vendor list — third parties with access to personal information
- Coordinator identity — designated WISP coordinator name/title, or confirmation none exists
- Supplemental frameworks — applicable laws beyond MA (GDPR, CCPA, HIPAA, GLBA, PCI-DSS)
Output Structure
Produce a formally numbered document with table of contents, definitions section, body sections below, and appendices as needed.
Section 1 — Executive Summary & Program Purpose
| Field | Content |
|---|
| Effective Date | [DATE] |
| Version | [N] |
| Governing Regulation | 201 CMR 17.00; [additional frameworks] |
| Scope | PI of MA residents owned, licensed, stored, or maintained by [Org] |
| Commitment Statement | One-paragraph executive commitment to administrative, technical, and physical safeguards |
Section 2 — WISP Coordinator Designation
- Name, title, department, direct contact
- Authority to implement, supervise, and maintain the program
- Reporting line to executive leadership, IT, and legal counsel
- If none exists: recommend qualifications and flag
[ACTION REQUIRED]
Section 3 — Risk Assessment Framework
- Methodology for identifying risks across the data lifecycle (collection → destruction)
- Risk matrix: likelihood × impact
- Scope: employee access, system vulnerabilities, physical gaps, third-party exposure
- Reassessment: annually minimum + after material organizational change
- Incorporate prior assessment findings and mitigation status if available
Section 4 — Security Safeguards
4A — Administrative
- Least-privilege access control