close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.
built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.
a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.
against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.
Top Panel
WHAT IS T2P?
Top Panel
Information & Operational Protection

Rules and guidance for security, integrity, and confidentiality of information and operations, including privacy guidelines that indicate broad-reaching data management practices.

Rules & Standards RSS
IssuerPurdue
Country US

An architectural framework for privacy practices, including technological and non-technical components and a roadmap for privacy policy development and enforcement.

IssuerAICPA/CICA
Country Multi

Aimed at accountants and accountancies, this framework incorporates elements of the OECD privacy guidelines, HIPAA, GLBA, PIPEDA, and other international rules and regulations.

IssuerHHS
Country US

HITECH Act - Health Information Technology for Economic and Clinical Health Act. Guidance relates to two forthcoming breach notifications - one to be issued by HHS for (HIPAA) covered entities and thier business associates and one to be issued by the Fede ...

IssuerRMI
Country Multi

Factor Analysis of Information Risk (FAIR) provides a framework for understanding, analyzing, and measuring information risk. The outcomes are more cost-effective information risk management, greater credibility for the information security profession, an ...

IssuerNIST
Country US

Practical (draft) guidance on IT principles and practices to support HIPAA privacy and information security standards.

IssuerFFIEC
Country US

Federal guidance for US financial services firms on risks and risk management controls necessary to authenticate the identity of customers accessing Internet-based services.

IssuerMicrosoft
Country Multi

Information security professionals traditionally had difficulty trying to justify their existence. IT security staff agree there should be some security controls in place, but trying to validate a defense in depth approach is difficult. Organizations ha ...

IssuerBSI
Country Multi

This book provides guidance on the implementation of ISMS control requirements for auditing existing control implementations to help organizations preparing for certification in accordance with ISO/IEC 27001:2005 Information security management systems. R ...

IssuerBSI
Country Multi

The British Standard, BS10012 Data protection. Specification for a personal information management system has been developed to establish best practice and aid compliance with data protection legislation. It is the first standard for the management of per ...

IssuerBSI
Country Multi

BS ISO/IEC 27000 aims to provide the terms and definitions, and an introduction to the ISMS family of standards that: * Define requirements for an ISMS and for those certifying such systems * Provide direct support, detailed guidance and/or in ...

IssuerUS
Country US

Regulation of unfair and deceptive acts and practices in connection with the collection and use of personal information from and about children on the Internet.

IssuerCIS
Country US

A set of key security outcome and practice metrics developed by a team of more than 150 government, private, and academic experts. Metrics cover the following business functions: * Application Security o Number of Applications ...

IssuerNERC
Country US

Requirements for the identification and documentation of Critical Cyber Assets through the application of a risk-based assessment. Part of the NERC CIP cybersecurity framework for the protection of the US Bulk Electric System.

★★★★★
IssuerKoops
Country Multi

A survey of existing and proposed global regulations related to cryptography, including a map of import, export, and domestic controls and a crypto and self-incrimination FAQ.

IssuerUS
Country US

Federal regulation covering requests for and disclosure of information retained by the US Government.

IssuerNERC
Country US

Standard for the identification and protection of an electronic security perimeter(s). Part of the NERC CIP cybersecurity framework for the protection of the US Bulk Electric System.

IssuerEU
Country EU

EU regulation covering the protection of individuals with regard to the processing of personal data and the free movement of such data.

IssuerFTC
Country US

The FTC Health Breach Notification Rule requires companies to contact customers, the FTC, and the media in the event of a security breach. The rule applies only to health information that is not secured through technologies specified by the Department of ...

IssuerIIA
Country Multi

Guidance on assessing and redressing privacy risks, aimed at internal auditors and managers. Includes abstracts of key privacy frameworks and guidance on privacy assessments.

IssuerIIA
Country Multi

Guidance for the assessment of vulnerability management practices, including specific managerial recommendations. Developed for audit executives and internal auditors.

IssuerIIA
Country Multi

General guidance for internal auditors and management on identity and access management (IAM) concepts, processes, and audit.

IssuerFTC
Country US

US law for financial institutions covering 1) requirements for the protection nonpublic personal information, 2) limitations and customer rights related to disclosure of personal information, and 3) requirements for clear and conspicuous disclosure of ins

IssuerUN
Country Multi

International guidance enumerating minimum guarantees that governments should make regarding the collection, retention, and use of personal electronic information.

IssuerHHS
Country US

A US regulatory standard for the protection of protected health information, including use and disclosure of health information, and standards for individual rights to control how health information is used.

IssuerHHS
Country US

A US national standard covering administrative, technical, and physical security procedures for covered entities to use to assure the confidentiality of electronic protected health information.

IssuerNERC
Country US

Standard for the identification, classification, response, and reporting of Cyber Security Incidents related to Critical Cyber Assets. Part of the NERC CIP cybersecurity framework for the protection of the US Bulk Electric System.

IssuerUS FFIEC
Country US

A chapter of the Federal Financial Institutions Examination Council (FFIEC) Information Technology Examination Handbook (IT Handbook) providing guidance to examiners and financial institutions on audit roles and responsibilities. General action indication ...

IssuerCERT
Country US

The IT Security EBK conceptualizes IT security skill requirements in a new way to address evolving IT security challenges. The EBK characterizes the IT security workforce and provides a national baseline representing the essential knowledge and skills tha ...

IssuerDE BSI
Country DE

An overview of IT security measurements and metrics written for non-experts. Emphasis on organizational safeguards and illustrating threats through practical examples.

IssuerGeer
Country Multi

A substantive presentation describing definition, souring, application, interpretation, testing, cost effectiveness, calibration, and use of security measurement in a risk context. The presentation also provides insights on related concepts, such as st ...