close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.
built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.
a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.
against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.
Top Panel
WHAT IS T2P?
Top Panel
Step-by-Step InfoSec and Business Continuity

These resources are part of the fairly vast Computer and Network Security Task Force wiki. Although the wiki is targeted at educational institutions, its information security recommendations and principles are, for the most part, applicable to corporate environments, as well.

Toolkits and Blueprints

  • Confidential Data Handling Blueprint: A step-by-step roadmap for the establishment of policies and practices for the protection of sensitive information. Includes categorized links to policy models, self-assessment tools, guidance on information classification, benchmarking resources, and much more.
  • Business Continuity Planning Toolkit: Includes planning tools, a disaster recovery planning guide, resources and templates for internal and external communications during a business disruption, good practice guidelines, an overview of business continuity for executives, and other research and advice
  • Data Classification Toolkit: A step-by-step roadmap for the data classification prerequisite of effective information protection. Includes links to regulatory requirements for classification, standards, case studies, and other guidance
  • Data Incident Notification Toolkit: Includes notification templates for Web and other media; sample policies, procedures, and plans; case studies; and guidance on notification thresholds
  • Model IT Security Training Materials: A collection of sample policy abstracts and quizzes (downloadable, MS PowerPoint format)
  • RFP models for information security risk assessment: Sample RFPs for larger and smaller organizations, designed to simplify the process of evaluating and engaging consultants for security risk assessment

 

Comments
RSS
Only registered users can write comments!

3.26 Copyright (C) 2008 Compojoom.com / Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."