Begin Main Content Area

IT Policies

Can't find what you're looking for? Try our policy search engine. 

Third-party vendors, licensors, contractors, suppliers, or offerors shall meet the policy requirements of the Commonwealth's Information Technology Policies (ITPs) that are applicable to the products and services provided to the Commonwealth.

Domain Title Supporting Documents Current Version
Access ITP_ACC001- Information Technology Digital Accessibility Policy
01/26/2021
Application ITP_APP030- Active Directory Architecture 10/25/2010
​Business ​ITP_BUS000-Information Technology Policy GovernanceOPD BUS000B
OPD BUS000C
OPD BUS000D
OPD BUS000E
10/26/2017​
Business​ITP_BUS001-IT Planning and Projects
​OPD_BUS001A
OPD_BUS001A word
02/04/2021
Business
ITP_BUS002-IT Investment Review Process

11/17/2020
Business
ITP_BUS003- RESCINDED: Emergency Telework Policy
08/02/2018
Business ITP_BUS004- IT Policy Waiver Review Process
OPD BUS004A
RFD BUS004B
03/20/2020
Business ITP_BUS007- Enterprise Service Catalog
07/19/2018
Business ITP_BUS008- Enterprise Employment Application Platform Policy 11/21/2016
​Business ITP_BUS010-Business Process Management Policy ​07/03/2017
​Business
ITP_BUS011-IT Service Organization Management and Cloud Requirements
OPD BUS011A
OPD-BUS011B
OPD-BUS011C
​12/01/2020
​Business
ITP_BUS012-Artificial Intelligence General Policy
RFD-BUS012A
RFD-BUS012B
​09/09/2020
Project
Management
ITP_EPM001- RESCINDED: Integrated Project and Portfolio Management System (iPPMS)
01/02/2019
Project 
Management
ITP_EPM006-RESCINDED: IT Strategic Planning and Projects 07/19/2019
​InformationITP_INF000- Enterprise Data and Information Management Policy
OPD INF000A12/22/2020
Information ITP_INF001- Database Management Systems
OPD INF001B 
1/15/2021
Information ITP_INF003- Data Modeling Standards BPD INF003C 
BPD INF003D 
STD INF003A 
STD INF003B
11/18/2010
Information ITP_INF004- Data Warehouse Policy BPD INF004B 
GEN INF004A 
GEN INF004D 
STD INF004C
11/18/2010
Information ITP_INF006- Commonwealth Code Standard
11/19/2018
Information
ITP_INF009- e-Discovery Technology Standard STD INF009A11/18/2010
Information ITP_INF010- Business Intelligence Policy GEN INF010B
STD INF010A
11/18/2010
Information ITP_INF011- Reporting Policy GEN INF011B
STD INF011A
11/18/2010
Information ITP_INF012- Dashboard Policy GEN INF012B
STD INF012A
11/18/2010
Information ITP_INFRM001- The Life Cycle of Records: General Policy Statement 11/18/2010
Information ITP_INFRM004- Management of Web Records 11/18/2010
Information ITP_INFRM005- System Design Review of Electronic Systems OPD INFRM005A11/18/2010
Information ITP-INFRM006 - Electronic Document Management Systems         RFD INFRM006C
STD INFRM006A
STD INFRM006B
5/13/2020
Information ITP_INFRM007- Management of Electronic Information created via non-EDMS technology 11/18/2010
Integration
ITP_INT_B_1- Electronic Commerce Formats and Standards 07/27/1999
Integration ITP_INT_B_2- Electronic Commerce Interface Guidelines BPD INT001B
STD INT001A
07/27/1999
Integration ITP_INT001- Message-Oriented Middleware 10/25/2010
Integration ITP_INT006- Business Engine Rules STD INT006A10/25/2010
Network ITP_NET001- Wireless LAN Technology 06/10/2016
Network ITP_NET002- Network Router and Switch Technology Standards GEN NET002B
10/31/2018
Network ITP_NET003- Enterprise Telecommunication Services

02/09/2021
Network ITP_NET004- Internet Protocol Address Standards OPD NET004A12/20/2010
Network ITP_NET005- Commonwealth External and Internal Domain Name Services (DNS)

OPD_NET005A

OPD-NET005B

03/17/2020
Network ITP_NET007- Cable/Satellite Television (CATV) Services OPD NET007A12/21/2010
Network ITP_NET008- Telecommunications Services for Commonwealth Business Partners 10/09/2015
Network ITP-NET009 RESCINDED: Video Conferencing Services for the Commonwealth of PA

2/09/2021
Network ITP_NET010- Commonwealth of Pennsylvania Satellite Services & Equipment Policy OPD NET010A
OPD NET010B
OPD NET010C
03/03/2011
Network ITP_NET016- Wireless Cellular Data Technology 06/15/2017
Network ITP_NET17_Network Timing Protocol
07/29/2018
Network ITP_NET018- Commonwealth Metropolitan Area Network (MAN) and Internet Access 09/13/2019
Network ITP_NET019- Virtual Desktop Infrastructure 11/13/2012
Platform ITP_PLT001- RESCINDED: Desktop and Laptop Technology Standards
02/02/2018
​Platform
ITP_PLT002 - Multi-Function Equipment Management Policy
​OPD-PLT002A
11/08/2019​

Platform
ITP_PLT004- RESCINDED: Statewide PC/Terminal Maintenance Contract
01/19/2018
Platform ITP_PLT005- Server Operating System Policy
01/16/2020
Platform
ITP_PLT010- RESCINDED: Management of Networked Multi-Function Equipment
01/09/2019
Platform ITP_PLT012- Use of Privately Owned PCs to Access CoPA Resources 06/06/2016
Platform
ITP_PLT015- RESCINDED: Office Class Printer Device Policy
01/09/2019
Platform ITP_PLT017- Desktop and Laptop Operating System Standards
            02/02/2020
​PlatformITP_PLT018- Commonwealth of PA Centralized E-Mail Policy​07/19/2019
​PlatformITP_PLT019- Web Server/Application Server Standards
​07/01/2017
IT Procurement
ITP_PRO001- RESCINDED: IT Procurement Review Process
07/22/2018
Privacy
ITP_PRV001- Commonwealth of Pennsylvania Electronic Information Privacy PolicyOPD_PRV001A
03/23/2018
Privacy
ITP_PRV002- Electronic Information Privacy Officer
OPD PRV002A11/18/2010
​SecurityITP_SEC000 - Information Security Policy
OPD_SEC000B
05/07/2020
Security
ITP_SEC001- Enterprise Host Security Software Policy

02/09/2021
Security ITP_SEC002- Internet Accessible Proxy Servers and Services 11/08/2005
Security ITP_SEC003- Enterprise Security Auditing and Monitoring 04/15/2020
Security ITP_SEC004- Enterprise Web Application Firewall 01/15/2010
Security ITP_SEC005- Commonwealth Application Certification and Accreditation 08/16/2011
Security ITP_SEC006- Commonwealth of Pennsylvania Electronic Signature Policy RFD-SEC006A07/01/2016
Security ITP_SEC007- Minimum Standards for IDs, Passwords and Multi-Factor Authentication 09/22/2020
Security ITP_SEC008- Enterprise E-mail Encryption 09/17/2010
Security ITP_SEC009- Minimum Contractor Background Checks Policy 03/23/2006
Security ITP_SEC010- Virtual Private Network Standards
06/23/2020
Security ITP_SEC011- Enterprise Policy and Software Standards for Agency Firewalls 04/16/2009
Security ITP_SEC012- Commonwealth of PA System Logon Banner and Screensaver Requirements
06/25/2020
Security ITP_SEC013- RESCINDED - Identity Protection and Access Management (IPAM) Architectural Standard Identity Management Services             08/11/2020
Security ITP_SEC014- RESCINDED - Identity Protection and Access Management (IPAM) Architectural Standard Identity Management Technology Standards             08/11/2020
Security ITP_SEC015- Data Cleansing Policy
OPD SEC015A10/04/2018
Security ITP_SEC016- Commonwealth of Pennsylvania - Information Security Officer Policy 03/16/2017
Security ITP_SEC017- CoPA Policy for Credit Card Use for e-Government 08/14/2013
Security ITP_SEC019- Policy and Procedures for Protecting Commonwealth Electronic Data            
12/17/2020
Security
ITP-SEC020 RESCINDED - Encryption Standards for Data at Rest
12/4/2020
Security ITP_SEC021- Security Information and Event Management Policy
05/9/2013
Security ITP_SEC023- Information Technology Security Assessment and Testing Policy
05/7/2015
Security ITP_SEC024- IT Security Incident Reporting Policy
2/16/2021
Security ITP_SEC025- Proper Use and Disclosure of Personally Identifiable Information (PII)
01/12/2018
Security ITP_SEC027- Standard for Electronic Postmarks 03/16/2007
Security ITP_SEC029- Physical Security Policy for IT Resources SEC029 REFERENCE06/21/2007
Security ITP_SEC031- Encryption Standards

12/4/2020
Security ITP_SEC032- Enterprise Data Loss Prevention (DLP) Compliance Standards 04/29/2011
Security ITP_SEC034- Enterprise Firewall Rule Set 08/28/2008
Security ITP_SEC035- Mobile Device Security Policy 04/06/2020
​SecurityITP_SEC037- RESCINDED - Identity Proofing of Online Users
12/07/2020

​Security ​ITP_SEC038- COPA Data Center Privileged User Identification and Access Management Policy​06/19/2018
​Security​ITP-SEC039 Keystone Login and Identity Proofing
​12/07/2020

Software ITP SFT000- Software Development Life Cycle (SDLC) Policy
08/15/2018
SoftwareITP_SFT001 Software Licensing02/22/2017
Software ITP_SFT002 Commonwealth of PA Design Standards
OPD-SFT002A 
04/01/2020
​SoftwareITP_SFT003- Geospatial Enterprise Service Architecture02/22/2017
Software ITP_SFT004 Geospatial Information Systems (GIS) 02/22/2017
​SoftwareITP_SFT005- Managed File Transfer (MFT)02/22/2017
Software ITP_SFT006- Internet Browser Policy 06/25/2020
​SoftwareITP_SFT007- Office Productivity Policy06/14/2019
Software ITP SFT008- Enterprise Resource Planning (ERP) Management 02/22/2017
Software ITP SFT009- Application Development 04/27/2018
System Management ITP_SYM003- Off-Site Storage for Commonwealth Agencies 12/20/2010
System Management ITP_SYM004- Policy for Establishing Alternate Processing Sites for Commonwealth Agencies OPD SYM004A
OPD SYM004B
05/22/2012
System Management ITP_SYM006- Commonwealth IT Resources Patching Policy  OPD SYM006A01/04/2017
System Management ITP_SYM008- Virtualization Policy
12/03/2019
System Management ITP_SYM010- Enterprise Change Management Maintenance Policy OPD SYM010A 12/03/2019