close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.

built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.

a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.

against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.

Top Panel
WHAT IS T2P?
Top Panel
* Maps & Crosswalks

Comparative analyses of major rules, frameworks, and standards.

Rules & Standards RSS
Issuer: US DoE
Country US

A section-level mapping of ISO/IEC 17799 (now 27002), NIST PCSRF - Security Capabilities Profile for Industrial Control Systems, and sections of ISA SP99 - Manufacturing and Control System Security Standard.

Issuer: Idaho Nat'l Lab
Country US

A section-level mapping of ISO/IEC 17799 (now 27002), IEEE 1402, and NERC security standards. Note: Current as of 2004.

Issuer: ISACA
Country Multi

A high-level mapping between COBIT IT governance framework, ITIL service management guidance, and ISO 27002 information security standard to support an overall governance and control framework based on an IT process model.

Issuer: ISACA
Country Multi

High-level mapping of the COBIT risk management framework, ITIL service management framework, and ISO 17799 (now 27002) security standard, including advice on how to meld all three standards into a comprehensive control framework.

Issuer: ISACA
Country Multi

A global overview of COBIT in relation to COSO, ITIL, ISO/IEC 17799:2005, FIPS Pub 200, ISO/IEC TR13335, ISO/IEC 15408, 2005, PRINCE2, PMBOK, TickIT, CMMI, TOGAF 8.1, IT Baseline Protection Manual, and NIST 800-14

Issuer: ISACA
Country Multi

A detailed cross-mapping of ITIL v3 with COBIT 4.1.

Country Multi

A detailed mapping of NIST SP800-53 (Rev 1) information security control standard with with COBIT 4.1.

Issuer: ISACA
Country Multi

A detailed mapping of TOGAF 8.1 architectural framework, issued by The Open Group, with COBIT 4.0.

Issuer: WEDI
Country US

From 2005, a heading-level cross-mapping of HIPAA with the ISO/IEC 17799 (now 27002) information security standard.

Issuer: WEDI
Country US

A heading-level cross-reference of two US federal information security rules.

Issuer: ISACA
Country Multi

Provides scoping and assessment ideas, approaches and guidance in support of the IT-related Committee of Sponsoring Organizations of the Treadway Commission (COSO) internal control objectives for financial reporting. Includes a COSO-to-COBIT mapping.

Issuer: ISACA
Country Multi

A mapping of COBIT 4.0 with a superseded version of the ISO 17799 information security standard.

Issuer: ISACA
Country Multi

A detailed mapping of ISO/IEC 17799:2005 information security standard with COBIT 4.0.

Issuer: ISACA
Country Multi

A detailed mapping of the IT Infrastructure Library (ITIL) IT service management guidance with COBIT 4.0.

Issuer: ISACA
Country Multi

a detailed mapping of A Guide to the Project Management Body of Knowledge (PMBOK Guide) Third Edition (2004), from the Project Management Institute (PMI), with COBIT 4.0.

Issuer: BITS
Country Multi

This document provides a linkage between the Shared Assessments Standardized Information Gathering (SIG) Questionnaire and certain federal regulatory requirements and international standards. This linkage is presented in the form of a "map" that highlight ...

Issuer: NIST
Country US

Contains an appendix cross-mapping HIPAA privacy and security requirements with various NIST 800 Series information security standards.

Issuer: ISACA
Country Multi

Val IT does not operate in a vacuum. Today, several other standards and collections of best practices are available that show how to manage specific facets of the IT projects and programs within enterprises. This publication provides a mapping to compare ...