Table of Contents
Information Security7
| Internet | 7 |
| Information Security Tools and Processes | 8 |
| Application security | 8 |
| Cloud security | 9 |
| Cryptography | 9 |
| Infrastructure security | 10 |
| Incident response | 10 |
| Vulnerability management | 11 |
| Security Concepts | 11 |
| Confidentiality | 11 |
| Integrity | 12 |
| Availability | 12 |
| People Accessing Information | 12 |
| Authentication | 13 |
| Authorization | 13 |
| Nonrepudiation | 13 |
| Information Security Risk Management | 14 |
| Risk Control | 16 |
| Unsecured Computers and Networks | 17 |
| Identify Theft | 18 |
| Identify Theft Methods | 19 |
| Trash Sifting/Dumpster Diving | 19 |
| Mail Theft | 20 |
| Address Manipulation: | 20 |
| Skimming | 21 |
| Scanning | 22 |
| Straightforward Theft: | 22 |
| Conning | 22 |
| Identify Theft Crimes | 23 |
| Yahoo Data Breach | 23 |
| Equifax breach | 23 |
| Target Data Breach | 24 |
| CPAs and Tax Practitioners are Being Targeted | 24 |
| Six Basic Safeguards | 25 |
| Install Operating System Updates | 25 |
| Antivirus Software | 26 |
| Malware Definition | 28 |
| Viruses and Worms | 29 |
| Virus | 29 |
| Worm | 30 |
| Trojans | 30 |
| Backdoor / Remote Access Trojan (RAT) | 31 |
| Botnets | 31 |
| Adware | 34 |
| Information stealers | 34 |
| Ransomware | 34 |
| Rootkits | 35 |
| Downloaders or droppers | 35 |
| File Wipers | 36 |
| Spyware | 36 |
| Spyware | 36 |
| Malware Summary | 37 |
| Review Questions | 38 |
| Review Question Answers | 41 |
| Phishing | 46 |
| Spear Phishing | 47 |
| Clone Phishing | 48 |
| Whale Phishing | 48 |
| Social Media Phishing | 49 |
| Phishing Evolution | 49 |
| Phishing Opportunities | 49 |
| Criminals are Learning and Evolving | 50 |
| Phishing Tools | 50 |
| Bots/Botnets | 50 |
| Phishing Kits | 50 |
| URL Obfuscation | 51 |
| Simple HTML redirection | 51 |
| Use of JPEG images | 51 |
| Use of alternate IP addresses | 51 |
| Registration of similar domain names | 52 |
| Web Browser Vulnerabilities used for Phishing | 52 |
| Session Hijacking | 52 |
| Domain Name Resolving Attacks | 53 |
| Global DNS Hijacking Campaign | 53 |
| Cross-Site Scripting Attacks | 54 |
| Domain Name Typos | 54 |
| Man-in-the-Middle Attacks | 55 |
| Phishing-Related Malware Examples | 55 |
| Bancos | 55 |
| Bankash | 55 |
| W32/Grams | 56 |
| CoreFloo | 56 |
| Dyre Banking Malware | 56 |
| Phishing Mitigations | 56 |
| Phishing Solutions | 57 |
| Prevent Phishing Attacks: | 57 |
| Firewalls | 58 |
| Two-factor authentication | 59 |
| Backup software/services | 59 |
| Drive encryption | 59 |
| Data security plan | 60 |
| Complying with the Safeguards Rule | 61 |
| Who Must Comply? | 61 |
| How to Comply | 61 |
| Securing Information | 62 |
| Employee Management and Training. | 62 |
| Information Systems. | 63 |
| Detecting and Managing System Failures. | 64 |
| Creating an Information Security Risk Management Plan | 65 |
| Identify Risks | 66 |
| Perform Risk Analysis | 68 |
| Plan Risk Responses | 70 |
| Implement Risk Responses | 72 |
| Monitor Risks | 72 |
| Basic Security Training | 73 |
| Use Security Software | 74 |
| Avoid Phishing and Malware | 74 |
| Protect Personal Information | 75 |
| Mobile Phone Security | 75 |
| Mobile Phone Theft | 76 |
| Securing Mobile Phones | 76 |
| Installing Apps with Malware | 76 |
| E-mail attachments | 77 |
| SMS links | 77 |
| Create Strong Passwords | 77 |
| Making Passwords More Secure | 78 |
| Password Managers | 79 |
| Making Online Accounts More Secure | 79 |
| Securing Data Networks | 80 |
| Install Operating System Updates Regularly | 80 |
| Run Antivirus Software on all Computers and Run Regular Scans | 81 |
| Keep Antivirus Software Updated | 81 |
| Practice Safe Online Activities | 82 |
| Use Both network Firewalls and Personal Firewalls | 82 |
| Implement Secure Passwords and Enhanced Security Features | 83 |
| Encrypt Client Data | 83 |
| Back Up all Data Regularly | 84 |
| Email Security | 84 |
| Email Security- Best Practices for Companies | 84 |
| Email Security - Best Practices for Individual Users | 88 |
| Intrusion Prevention Systems (IPS) | 91 |
| Mobile Device Security | 92 |
| Network Segmentation | 92 |
| Virtual Private Network (VPN) | 93 |
| Physical Security | 94 |
| Disposing of Equipment Securely | 94 |
| Techniques for Removing Information | 95 |
| Deleting information | 96 |
| Overwriting information | 96 |
| Secure Erasure | 96 |
| Physical destruction | 97 |
| Disposing of Mobile Phones and Tablets | 97 |
| Signs of Data Theft | 98 |
| Data Theft Clues | 99 |
| What Happens if you are Hacked? | 99 |
| Preliminary steps include: | 99 |
| Data Loss Reporting | 101 |
Review Questions102
Review Question Answers104
Glossary109
Index113
Course Details
Author: Andrew Clark, EA
Publication/Revision Date: 3/29/2026
Course Exam Questions (online): 30 (multiple-choice)
Program Delivery Method: Self-Study (NASBA QAS Self-Study)
Available Formats of Course Text: PDF or PDF plus printed copy sent in the mail
Course Level, Prerequisites, and Advance Preparation Requirements
| License | Course Level | Prerequisites | Advance Preparation Requirements |
|---|
| CPA | Overview | None | None |
| CFP® | Intermediate | None | None |
| EA/OTRP | Intermediate | None | None |
* This program is appropriate for professionals at all organizational levels.
Sponsor ID Numbers
National Registry of CPE Sponsors ID: 107615
CFP Board Sponsor ID: 1008 — Course ID: 763277
IRS Qualified Sponsor ID: FWWKO — Course ID: FWKK0-T-00793-26-S
State CPA Board Sponsor ID Numbers (where applicable)
Florida Division of Certified Public Accounting: 0004761
Hawaii Board of Public Accountancy: 14003
New York State Board for Public Accountancy: 002146
Ohio Accountancy Board: CPE .51 PSR
Pennsylvania State Board of Accountancy: PX178025
Texas State Board of Public Accountancy: 009349
Learning Objectives
As a result of studying the course material, you should be able to meet the objectives listed below:
- Identify the importance of information security for CPAs and Tax Practitioners,
- Define the term “identify theft” and recognize how identify theft most commonly occurs,
- Recognize why CPAs and Tax Professionals are being targeted by cybercriminals,
- Recognize the importance of encrypting client data,
- Identify the importance of creating internal controls and a security plan to protect client data, and
- Recognize the actions that must be taken in the event of a breach of sensitive client identity data.