close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.

built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.

a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.

against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.

Top Panel
WHAT IS T2P?
Top Panel
Governance & Risk Management

Standards, frameworks, and rules for risk management, high-level oversight, and business and operational governance.

Rules & Standards RSS
Issuer: AICPA
Country US

Aimed at accountants and accountancies, this guide presents a framework for IT assurance and advisory services related to information security; system or service availability, processing and integrity; and online privacy and confidentiality.

Issuer: RMI
Country Multi

Factor Analysis of Information Risk (FAIR) provides a framework for understanding, analyzing, and measuring information risk. The outcomes are more cost-effective information risk management, greater credibility for the information security profession, an ...

Issuer: BIS
Country Multi

A complex regulatory requirement and framework for banks, Basel II encourages a measured risk-based approach to capital management. The rule adds emphasis to the need for comprehensive, integrated data management, including data quality controls.

Issuer: ISACA
Country Multi

An IT governance framework and supporting toolset that helps managers bridge the gap between control requirements, technical issues, and business risks. (Free site registration required to download.)

Issuer: COSO
Country Multi

Defines essential enterprise risk management components, discusses key ERM principles and concepts, suggests a common ERM language, and provides clear direction and guidance for enterprise risk management.

Issuer: COSO
Country Multi

Establishes a general foundation for planning, implementing, assessing, and improving internal controls.

Issuer: ZA IODSA
Country ZA

The South African corporate governance code, including guidance on board constitution, qualifications, oversight responsibilities, and compensation. Written for relevance to governmental, public for-profit, and non-profit entities.

Issuer: Geer
Country Multi

A substantive presentation describing definition, souring, application, interpretation, testing, cost effectiveness, calibration, and use of security measurement in a risk context. The presentation also provides insights on related concepts, such as st ...

Issuer: CLUSIF
Country Multi

Guidance on building information security plans, compliant with ISO 13335 risk management standard and compatible with ISO 27001.

Issuer: NIST
Country US

Asset identification plays an important role in an organization's ability to quickly correlate different sets of information about assets. NISTIR 7693 provides the necessary constructs to uniquely identify assets based on known identifiers and/or known in ...

Issuer: PCAOB
Country US

Superseded by PCAOB Auditing Standard No. 5 in July 2005. Comprehensive standard for public company audit and assurance efforts required by the Sarbanes-Oxley Act of 2002.

Issuer: PCAOB
Country US

Comprehensive audit standard supporting public-company audit and assurance efforts required by the Sarbanes-Oxley Act of 2002.

Issuer: US
Country US

US anti-fraud legislation covering financial practice and corporate governance.

Issuer: CORAS
Country Multi

A practical framework for model-based risk management of security-critical systems by exploiting the synthesis of risk analysis methods with semiformal specification methods, supported by an adaptable open source tool-integration platform. Accompanied by

Issuer: IRM
Country UK

Practical guidance on the application of business risk-management principles, with perspectives on both the upside and a downside of risk. Developed by a consortium of UK risk management associations.

Issuer: UK FRC
Country UK

The US Securities and Exchange Commission (SEC) has identified the Turnbull guidance as a suitable framework for complying with US requirements to report on internal controls over financial reporting, as set out in Section 404 of the Sarbanes-Oxley Act of