Anyone made a Written Info Security Plan (WISP) before?
4 months ago
My job is asking me to make one since I'm "the guy who knows tech". Which is ... It's not Wrong but it's also I only know tech compared to the other people I work with who are fully technically illiterate. I've been sinking tons of hours into this project just reading publications and trying to figure out what I'm doing. I don't suppose anyone here is better versed in these things and can help.
jmlop0
~jmlop0
Maybe go look for a consultant? Cause just from looking it up it seems like a pretty important thing.
Sticks
~sticks271
Not really what I do all day, but it's a high level document that talks about where your data is, how it's secured, who is responsible, etc. NIST 800-171 (and 800-53 but maybe not to start) are big long sets of controls that are good ideas standardized. You probably don't *have* to meet them but they should give you an idea. Having said all that, if this is a serious initiative I agree, get a consultant who can guide you through this. Definitely do that if you have a regulatory requirement.
FA+
