What Should Be in a Dealership’s WISP?

If your equipment dealership offers financing or leasing, you’re expected to have a Written Information Security Program (WISP). But what does that actually look like in practice?
A dealership WISP is a living document that spells out how you safeguard customer information—who owns the program, which risks you’ve identified, and what controls you’re using to manage them. If your “WISP” is a generic one-page policy or doesn’t exist at all, you’re exposed.
The Role of a WISP in Compliance
The WISP is the backbone of your Safeguards Rule compliance. It:
Defines your information security objectives.
Describes how you identify, manage, and monitor risk.
Connects your policies, procedures, and technical controls into a coherent program.
Gives auditors and lenders a way to see that you’re not just checking boxes—you’re managing risk on purpose.
Without a WISP, you have no defensible way to show that your safeguards are reasonable for your dealership’s size and complexity.
The 9 Core Elements Your WISP Should Cover
While wording can vary, a dealership-ready WISP should address at least these nine areas:
Program Governance & Qualified Individual
Who is responsible for your security program?
How are decisions made and reported to ownership?
Risk Assessment
Where does customer information live (systems, email, paper, vendor platforms)?
What internal and external risks have you identified?
Access Controls & Authentication
Who can access which data, and based on what criteria?
How do you enforce unique logins, strong authentication, and least-privilege access?
Data Encryption & Handling
How is customer information protected in transit and at rest?
How are backups handled and secured?
Secure Development & Change Management
How do you evaluate changes to systems or processes that touch customer data?
How do you avoid introducing new vulnerabilities inadvertently?
Vendor Management
Which service providers receive customer information?
How do you vet them and ensure they maintain appropriate safeguards?
Monitoring, Testing & Logging
How do you monitor for suspicious activity or failures?
How often do you test your controls (e.g., periodic reviews, external tests)?
Incident Response Plan
What happens if you experience a breach or serious security incident?
Who is involved, and how is communication handled with customers, lenders, OEMs, and regulators?
Training & Continuous Improvement
How often are employees trained on cybersecurity and data handling?
How do you update the WISP when risks, systems, or regulations change?
If your current document doesn’t clearly address these areas, it’s time for a refresh.
Avoiding Common WISP Mistakes
Dealers often get into trouble by:
Using a generic template that doesn’t reflect their actual operations.
Failing to keep the WISP updated as they add locations, systems, or vendors.
Treating the WISP as a one-time project instead of an ongoing governance tool.
Keeping the WISP completely separate from day-to-day processes and training.
A realistic WISP should be something your leadership can understand and use—not a binder that collects dust on a shelf.
How IronShield Builds Dealership-Specific WISPs
IronShield Advisors helps dealerships:
Translate FTC requirements into practical, dealership-language policies.
Map controls to real systems (DMS, CRM, email, file shares, vendor portals).
Create an incident response plan that matches your staffing and resources.
Align training and vendor oversight with the commitments in your WISP.
You end up with a document you can show to lenders, OEMs, and insurers, and a program you can actually follow.
If you’re not sure whether your current WISP would hold up in an audit, IronShield can walk you through a focused review and update plan tailored to your store.



Comments