close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.

built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.

a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.

against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.

Top Panel
WHAT IS T2P?
Top Panel

Tags:standard

Rules & Standards RSS
Issuer: NIST
Country US

Guidelines for incident handling, particularly for analyzing incident-related data and determining the appropriate response to each incident.

Issuer: NIST
Country US

US federal guidance on managing a continuous supply of log data; managing log generation and storage; protecting the confidentiality, integrity, and availability of logs; and performing effective analysis of log data.

US federal standard for installing, configuring, and maintaining secure servers

Issuer: NIST
Country US

US federal guidelines for the development, selection, and implementation to be used at information system and program levels to assess the effectiveness of security controls.

Issuer: NIST
Country US

US federal guideline describing three types of solutions: full disk encryption, volume and virtual disk encryption, and file/folder encryption. Recommendations for implementing and using each type.

Issuer: NIST
Country US

Describes the characteristics of IDPS technologies and provides recommendations for designing, implementing, configuring, securing, monitoring, and maintaining them.

Issuer: NIST
Country US

A broad overview of information security program elements to assist US federal agency managers in understanding how to establish and implement an information security program.

Issuer: NIST
Country US

This publication provides recommendations for using two vulnerability naming schemes: Common Vulnerabilities and Exposures (CVE) and Common Configuration Enumeration (CCE). SP 800-51 Revision 1 gives an introduction to both naming schemes and makes recomm ...

Issuer: NIST
Country US

This project supports the US Department of Homeland Security (DHS) Software Assurance Tools and R&D Requirements Identification Program. The objective of part 3, Technology (Tools and Requirements) is the identification, enhancement and development of sof ...

Issuer: NIST
Country US

Guidance on challenges related to integration of information security practices into Web service-based SOA design and development. Practical guidance on standards applicable to Web services and common security threats to SOAs based on Web services.

Issuer: NIST
Country US

US federal guidelines for selecting and specifying security controls for information systems.

Issuer: NIST
Country US

The draft Federal Information Processing Standard (FIPS)180-4 is a proposed revision of FIPS 180-3. Draft FIPS 180-4 adds a general procedure for creating an initialization hash value and two additional secure hash algorithms: SHA-512/224 and SHA-512/256, ...

NIST SP 800-144 provides an overview of the security and privacy challenges for public cloud computing and gives recommendations that organizations should consider when outsourcing data, applications, and infrastructure to a public cloud environment. ...

Issuer: NIST
Country US

NIST Special Publication 800-125 discusses security concerns associated with full virtualization technologies for server and desktop systems, and gives recommendations for addressing these concerns.

Issuer: NIST
Country US

This document includes most of the current terms & definitions used in NIST information security publications and those in the CNSS Instruction # 4009 (Glossary of Information Assurance terms). The document is meant to be a reference for Federal gover ...

Issuer: NIST
Country US

US federal standard describing technologies and features of SSL VPNs, how SSL fits within the context of layered network security, and a phased approach to SSL VPN planning and implementation.

Issuer: NIST
Country US

Asset identification plays an important role in an organization's ability to quickly correlate different sets of information about assets. NISTIR 7693 provides the necessary constructs to uniquely identify assets based on known identifiers and/or known in ...