|
Online tool provides deceptively simple decidedly serious support for business information governance and compliance
Seattle, WA June 8, 2009 -- The information governance research community Truth to Power today unveiled the Control & Risk Calculator (CRC), a free online tool for compliance, risk, and audit management. The tool is available at http://www.t2pa.com/crc. The Control & Risk Calculator supports business efforts to improve internal controls related to information security and privacy, business process management, data management, e-discovery, business continuity, change management, and other information-intensive processes. Effective execution of these controls is critical to meeting both business performance goals and compliance obligations. Incorporating user inputs and key principles from widely accepted audit, information governance, and risk management standards, the CRC rates factors from control strength to residual-risk severity. These calculations culminate in simple risk-based action recommendations. As a general risk management support tool, the CRC can be used to: - Record and track existing information controls
- Assess the effectiveness of controls against recognized risk
- Expose gaps in compliance and information governance
- Evaluate the impact of operational and environmental changes on control effectiveness
- Prioritize information governance efforts based on current control conditions
"Risk is complex," said T2P Community Founder Cass Brewer. "Although many frameworks exist to help businesses recognize risk complexity, far fewer resources support risk-sensitive internal-control decisions. The CRC is designed to fill this gap concretely, intelligently, and accessibly." Companies can use CRC findings to improve business processes, technology systems, and data sets. T2P expects the CRC to be of greatest use to strategic managers, information security managers, and internal auditors who oversee organizational risk and compliance programs. The CRC is available online at http://www.t2pa.com/crc. Membership in the T2P information governance research community is required for access. There is no charge for T2P membership, which unlocks all T2P research and community resources. Truth to Power: No-Hype, No-Bias Support for Information GovernanceT2P's development of the Control & Risk Calculator reflects the organization's mission to support the information governance community with concrete research, tools, and advice. Other useful T2P resources include: T2P resources are independently developed and vendor neutral. Find more information on T2P's spin and bias controls at http://www.t2pa.com/spin-and-bias-controls. ### About Truth to Power, LLC.Founded on the principles of knowledge, utility, credibility, and community, Truth to Power, LLC provides critical information resources for humans and machines. T2P's guiding principles are: 1) To provide genuinely useful, unbiased business research and resources that help businesses reduce operational costs and uncover capital opportunities; 2) To reveal alignment between siloed business disciplines, organizations, frameworks, and practices; and 3) to enable and encourage community members to share practical experience and expertise towards a common good. Membership and resources are free. Be a part of Truth to Power at http://www.t2pa.com/. Media Contact: T2P Media Relations
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
This e-mail address is being protected from spambots. You need JavaScript enabled to view it 1-(206)-407-3022 |
|
|
Free research resource offers practical, experience-based advice for improving the efficiency and effectiveness of PCI compliance and information security programs. Seattle, WA, May 19, 2009 --(PR.com)-- Truth to Power (T2P) today announced the release of new guidance for PCI compliance with the Payment Card Industry Data Security Standard (PCI DSS). The paper "PCI: Requirements to Action" addresses common questions and challenges associated with the protection of sensitive cardholder data, offering practical, experience-based pointers for more efficient, effective compliance. "The question is not whether PCI can represent effective security: it can. However, it must be supported by both a programmatic framework and a solid technical backbone," says Cass Brewer, founder of the Truth to Power research community. "By providing free and practical guidance for both top-down and bottom-up support for PCI, T2P seeks with this paper to help companies make the most of PCI compliance while avoiding its cost and process pitfalls." "PCI: Requirements to Action," supports integration of PCI data protection criteria into strategic risk- and security-management programs. The paper provides: - An informed analytical perspective on PCI control requirements
- Concrete advice on how to use PCI to build and advance the overall organizational security program
- Key recommended resources for information security strategy and execution
- A translation of PCI assessment requirements into implementation actions
"PCI: Requirements to Action - Practical guidance for more efficient, effective compliance" is available online at http://www.t2pa.com/pci-research. Knowledge by and for the Information Governance Community"PCI: Requirements to Action" is authored by Benjamin Tomhave, MS, CISSP, and reflects T2P's goal to facilitate the cross-pollination of experience-based knowledge within the information governance community.
"Benjamin Tomhave exemplifies the ability of knowledgeable professionals to advance the information security field as a whole," Brewer said. "His willingness to share his own practice-based insight and engage with other information security professionals means that everyone can learn from his experiences. It's a unique and valuable resource, and it's a model we hope many others will follow."
Tomhave also supports the information governance community as a T2P Expert Core Guide. His advice and commentary fuel T2P's Practical Security Core, available online at http://www.t2pa.com/cores/security-and-privacy/practical-security. Truth is Power: Open Research and Resources"PCI: Requirements to Action" embodies Truth to Power's mission to build a common platform of practical knowledge, research, tools, and advice for business governance, risk management, and compliance. By approaching practices such as compliance, data governance, e-discovery, project management, and performance management in terms of process and information governance, T2P helps organizational leaders find the commonalities and optimization opportunities that span conventional business practices and operational roles. T2P seeks to free managers, auditors, and other information governance professionals from knowledge boundaries and conceptual limitations that obscure risk opportunities and impede business performance. Research releases such as "PCI: Requirements to Action" support this goal as part of a rapidly growing research base that includes: - T2P Rules & Standards Hub: a free knowledgebase of more than 100 regulations, frameworks, and other guidance for information security, records management, IT auditing, IT investment management, and more
- IT Policy Templates Wiki: an open, collaborative repository of dozens of customizable policies for information security, data management, change management, and more.
- Good Free Tools: A knowledbase of free, authoritative, and interactive resources that support GRC goals
- Filtered News Feeds: Daily categorized news updates, painstakingly vetted and filtered from hundreds of news sources for relevance and utility
All T2P resources are free, many are collaborative, and each is vetted against hype and bias. More information to T2P's spin and bias controls is available at http://www.t2pa.com/spin-and-bias-controls.
### About Truth to Power, LLCFounded on the principles of knowledge, utility, credibility, and community, Truth to Power, LLC provides critical information resources for humans and machines. T2P's guiding principles are: 1) To provide genuinely useful, unbiased business research and resources that help businesses reduce operational costs and uncover capital opportunities; 2) To reveal alignment between siloed business disciplines, organizations, frameworks, and practices; and 3) to enable and encourage community members to share practical experience and expertise towards a common good. Membership and resources are free. Be a part of Truth to Power at http://www.t2pa.com/. Media Contact: T2P Media Relations
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
1-(206)-407-3022 |
"No-bull, no-bias" principle, strong research foundation, and collaborative community platform plug the gaps for business, IT, audit, and legal professionals.
SEATTLE, WA – Nov. 5, 2008 – Truth to Power, LLC today announced the formal launch of the Truth to Power Association (T2P, http://www.t2pa.com) a major independent research and community portal dedicated to improving business governance by improving the way businesses govern information.
"T2P is a no-bull, no-bias bridge between business governance, risk management, and compliance (GRC) practices that underpin business profitability and sustainability," says T2P founder Cass Brewer. "By providing a common-sense research and knowledge hub, we're building a central nervous system for business and technology intelligence—literally, a brain the size of the planet. Everyone can tap into it."
T2P works with thought leaders, industry associations, practitioners, and businesses to build a common platform of practical knowledge, research, tools, and advice for business governance, risk management, and compliance. By approaching issues such as Sarbanes-Oxley compliance, PCI, data protection, e-discovery, project management, and performance management at the process and information levels, T2P helps corporate leaders to find the commonalities and optimization opportunities that span conventional business practices and organizational roles.
Knowledge is Power: Free Research and Resources
T2P seeks to free managers, auditors, and other GRC professionals from knowledge boundaries and conceptual limitations that obscure risk opportunities and impede business performance. To support this goal, T2P's fast-growing research base includes:
- T2P Rules Hub: a free knowledgebase of key regulations, frameworks, and other guidance for information security, records management, IT auditing, IT investment management, and more
- IT Policy Wiki, part of the GRC Community Wiki Projects: an open, collaborative repository of dozens of customizable policies for information security, data management, change management, and more.
- U2P Advise & Act Roster: a running chronicle of standards drafts and rules proposals open to community comment.
- GRCpedia Wiki, part of the GRC Community Wiki Projects: An open, collaborative bank of governance, risk management, and compliance terminology
- Good Free Tools: A database of free, authoritative, and interactive resources that support GRC goals
- Filtered News Feeds: Daily categorized news updates, painstakingly vetted and filtered for relevance and utility from hundreds of news sources
In addition, T2P publishes a growing body of original analysis and advice offering unique, practical insight on specific business, technology, audit, and regulatory issues. All of these resources are free, many are collaborative, and each is vetted against hype and bias.
Community is Authority: Truth to Power Cores
T2P is the first open publishing resource to cultivate the cross-pollination of experience-based GRC knowledge in fields as disparate as process improvement, practical security, data governance, and eco-auditing. Truth to Power Cores are topical resource portals run by community experts with extraordinary knowledge of business, IT, audit, and legal practices. By sharing practice-based insight and collaborative interaction, Core Guides provide a rare source of vendor-neutral analysis and advice.
"IT and business leaders make their own decisions; often the 'official' guidance is just a starting point. T2P Core Guides are committed thought leaders with deep experience in their chosen areas—often with battle scars to prove it. We are deeply honored to be able to offer their practical insight and accessibility. Now everyone can benefit from what they've learned," Brewer says.
More Truth, More Power
In coming months, T2P will expand its support of the GRC community through:
- New education and research offerings, additional Cores, and free interactive tools
- Formal and informal relationships with other organizations and associations that support business and IT governance
- Community projects and working groups with concrete solution objectives.
To access new offerings, subscribe to progress reports, and be notified of new project openings, interested parties may register at no cost at T2P's Web site, http://www.t2pa.com.
About Truth to Power, LLC and T2P
Founded on the principles of knowledge, utility, credibility, and community, Truth to Power, LLC provides critical information resources for humans and machines. T2P's guiding principles are: 1) To provide genuinely useful, unbiased business research and resources that help businesses reduce operational costs and uncover capital opportunities; 2) To reveal alignment between siloed business disciplines, organizations, frameworks, and practices; and 3) to enable and encourage community members to share practical experience and expertise towards a common good. Membership and resources are free. Be a part of Truth to Power at http://www.t2pa.com/.
Media Contact T2P Media Relations
This e-mail address is being protected from spambots. You need JavaScript enabled to view it
1-(206)-407-3022 |
|
Truth to Power's integrated marketing and underwriting programs empower solutions providers and other business entities to multiply the power of communications through targeted positioning, direct interaction, and credible word-of-mouth referrals within the T2P community.
The T2P media kit includes descriptions of our analytical, research, and marketing offerings, along with an editorial calendar of our planned publications throughout 2009. Content includes:
- T2P Member demographics
- Online branding and lead generation programs
- Special information on T2P Solution Cores—multimedia-enabled, content-intensive portals just for commercial thought leaders
- Research underwriting programs
- Our 2009 research and editorial calendar
- White label publishing and research services
T2P media and marketing programs feature flexible structures, bundle discounts, and flexible pricing structures.
In addition to structured marketing programs, T2P also offers custom editorial, design, research, and marketing services that help solution providers leverage the expertise of T2P staff within their own marketing and research initiatives.
|

|
Banner advertising supports T2P contributors and content. Click here for available banner positions and sizes.
|
|
|