Skip to main content
written information security program (WISP)

Practices

Written Information Security Program (WISP)

A written information security program, or WISP, is the cornerstone of an information governance program. It can assist organizations in mitigating the risk of a cyberattack or the inadvertent disclosure of sensitive information and may also provide a legal defense for data breach-related claims. Pursuant to Ohio’s cybersecurity safe harbor law (2018 SB 220), implementing and maintaining a WISP can provide businesses with an affirmative defense against certain claims alleging that a failure to implement and maintain reasonable security standards resulted in a data breach.

An organization may also be required by data protection laws and regulations to execute a WISP to protect health and medical data, or other types of personally identifiable information.

Thompson Hine can assist your organization with drafting a comprehensive WISP that satisfies Ohio’s cybersecurity safe harbor law or other legal requirements.

WISP Framework

Legal RequirementsBiometric DataOversight and Management
EncryptionIT Risk ManagementAsset Inventory
Personnel SecurityIncident ManagementNetwork Monitoring
Network ManagementTrade SecretsFirewalls
Safe Harbor StandardsEnvironmental SecurityPassword Policy
Remote AccessAcceptable UseBusiness Continuity
Net Diligence Breach Coach Silver
Data Protection Guidebook 2025
Data Protection Map

If your organization has suffered a data breach or incident, please contact us at any time (24/7) at DataBreachResponse@ThompsonHine.com or fill out our online form below.


Name*
First
Last
Address
Street Address
Address Line 2
City
State / Province
ZIP / Postal Code
Area(s) of Concern

We respect your privacy. For a summary of what information we collect about you, the limited times when we may share it with others, and how we protect your privacy, please click on “Privacy Policy”.

A survey of U.S. Federal and State Laws, Statutes, and Regulations Governing Data Breach Notification, Biometric Information, Cybersecurity, and Data Privacy*

*The content is for general information purposes only and does not constitute legal or professional advice.