Begin Main Content Area

​​​​​​​ IT Policies

Can't find what you're looking for? Try our policy search engine. 

Third-party vendors, licensors, contractors, or suppliers shall meet the policy requirements of the Commonwealth's Information Technology Policies (ITPs) that are applicable to the products and services provided to the Commonwealth.

Domain Title Supporting Documents Current Version
Accessibility ITP_ACC001- Information Technology Digital Accessibility Policy

02/07/2023
​Business ​ITP_BUS000-Information Technology Policy Governance
​OPD BUS000B
OPD BUS000C
OPD BUS000D
OPD BUS000E
07/23/2021​
Business ​ITP_BUS001-IT Planning and Projects
​OPD_BUS001A
OPD_BUS001A word
OPD_BUS001B
01/23/2023
​Business
ITP_BUS002-IT Investment Review Process 
RFD-BUS002B
03/27/2023
Business ITP_BUS004- IT Policy Waiver Review Process
RFD BUS004B
03/04/2022
Business ITP_BUS007- Enterprise Service Catalog
07/19/2018
Business ITP_BUS008- Enterprise Employment Application Platform Policy
11/21/2016
​Business ITP_BUS010-Business Process Management PolicyGEN-BUS010A
OPD-BUS010B
OPD-BUS010B word
OPD-BUS010C
OPD-BUS010C word
​06/27/2022
​Business
ITP_BUS012-Artificial Intelligence General Policy
RFD-BUS012A
RFD-BUS012B
08/29/2022
Business
​ITP_BUSFM013- Enterprise Software Asset Management Policy
RFD-BUSFM013A
RFD-BUSFM013B
RFD-BUSFM013C
​03/27/2023
Business
ITP_BUS014- Commonwealth Use of Public Generative Artificial Intelligence
​09/21/2023
​InformationITP_INF000- Enterprise Data and Information Management Policy
OPD INF000A
05/27/2022
Information ITP_INF001- Database Management Systems
OPD INF001B 
03/09/2022
Information ITP_INF003- Data Modeling Standards
BPD INF003C 
BPD INF003D 
STD INF003A 
STD INF003B
09/09/2022
Information ITP_INF004- Data Warehouse Policy
BPD INF004B 
GEN INF004D 
STD INF004C
03/27/2023
Information ITP_INF006- Commonwealth Code Standard

09/09/2022
Information
ITP_INF009- e-Discovery Technology Standards
STD INF009A
11/10/2021
Information ITP_INF010- Business Intelligence Policy
GEN INF010B
STD INF010A
12/02/2022
Information ITP_INF011- Business Intelligence Reporting Policy
GEN INF011B
STD INF011A
12/02/2022
Information
ITP_INF012- Business Intelligence Dashboard Policy
GEN INF012B
STD INF012A
07/18/2023
​Information
​ITP_INF014 Standard for Electronic Postmarks
(FORMERLY ITP_SEC027)

​11/29/2021
Information
ITP_INF015- Policy and Procedures for Identifying, Classifying, and Categorizing Commonwealth Electronic Data

02/15/2024
Information ITP_INFRM001- The Life Cycle of Records: General Policy Statement

01/20/2023
Information ITP_INFRM004- Management of Web Records

06/22/2021
Information ITP_INFRM005- System Design Review of Electronic Systems
OPD INFRM005A
03/14/2023
​Information
ITP-INFRM006 - Electronic Document Management Systems
RFD
INFRM006C

STD
INFRM006A

STD
INFRM006B

​07/19/2021
Information ITP_INFRM007- Management of Electronic Information created via Multi-Function Devices or Other non-EDMS Desktop Scanners

12/01/2022
​Integration
ITP_INT001 - Message-Oriented Middleware
BPD_INT001B
STD_INT001A
07/12/2021
Integration
ITP_INT002- Electronic Commerce Formats and Standards
(FORMERLY ITP-INT_B1)
STD_INT002A
12/01/2022
Integration ITP_INT003- Electronic Commerce Interfaces
(FORMERLY ITP-INT_B2)

01/20/2023
Integration ITP_INT006- Business Rules Engine
STD INT006A
12/12/2022
Network ITP_NET001- Wireless LAN Technology
STD_NET001A
04/08/2022
Network ITP_NET002- Network Router and Switch Technology Standards
GEN NET002B
01/05/2024
Network ITP_NET003- RESCINDED

10/03/2023
Network ITP_NET004- Internet Protocol Address Standards
OPD NET004A
01/05/2024
Network ITP_NET005- Commonwealth External and Internal Domain Name Services (DNS)

OPD_NET005A

OPD-NET005B

07/23/2022
Network ITP_NET007- Cable/Satellite Television (CATV) Services
11/07/2022
Network ITP_NET008- Telecommunications Services for Commonwealth Business Partners

06/16/2022
Network ITP_NET010- Commonwealth of Pennsylvania Satellite Services & Equipment Policy
10/28/2022
Network ITP_NET016- RESCINDED

10/03/2023
Network ITP_NET017-Network Timing Protocol

05/23/2023
Network ITP_NET018- Commonwealth Metropolitan Area Network (MAN) and Internet Access07/29/2022
NetworkITP_NET019- Virtual Desktop Infrastructure
12/21/2021
​Platform
​ITP_PLT002 - Multi-Function Equipment Management Policy
OPD-PLT002A
12/21/2021​

Platform ITP_PLT005- Server Operating System Policy
STD-PLT005B
12/15/2022
Platform ITP_PLT012- Use of Privately Owned Devices to Access IT Resources
10/18/2021
Platform ITP_PLT017- Desktop and Laptop Operating System Standards
OPD-PLT017A
STD-PLT017C         
09/26/2023
​PlatformITP_PLT018- Commonwealth of PA Centralized E-Mail Policy08/29/2022
​PlatformITP_PLT019- Web Server/Application Server StandardsSTD-PLT019A
​01/30/2023
Privacy
ITP_PRV001- Commonwealth of Pennsylvania Electronic Information Privacy Policy OPD_PRV001A
03/23/2018
Privacy
ITP_PRV002- Electronic Information Privacy Officer
OPD PRV002A11/18/2010
​SecurityITP_SEC000 - Information Security Policy
OPD_SEC000B
07/18/2023
Security
ITP_SEC001- Enterprise Host Security Software Policy

07/18/2023
Security ITP_SEC002- Internet Accessible Reverse-Proxy Servers and Services
11/29/2023
Security ITP_SEC003- Enterprise Content FIltering Standard
01/16/2024
Security ITP_SEC004- Enterprise Web Application Firewall

11/29/2023
Security ITP_SEC005- Commonwealth Application Certification and Accreditation
09/07/2023
Security ITP_SEC006- Commonwealth of Pennsylvania Electronic Signature Policy
RFD-SEC006A
01/04/2024
Security ITP_SEC007- Minimum Standards for IDs, Passwords, Sessions and Multi-Factor Authentication
10/28/2022
Security ITP_SEC008- Enterprise E-mail Encryption
07/26/2023
Security ITP_SEC009- Minimum Contractor Background Checks Policy

03​/04/2024
Security ITP_SEC010- Virtual Private Network 

09/26/2023
Security ITP_SEC011- Enterprise Policy and Software Standards for Agency Firewalls

07/26/2023
Security ITP_SEC012- Commonwealth of PA System Logon Banner and Screensaver Requirements

11/29/2023
Security ITP_SEC015- Data Cleansing Policy
OPD SEC015A
OPD_SEC015A_word
07/26/2023
Security ITP_SEC016- Commonwealth of Pennsylvania - Information Security Officer Policy12/01/2023
Security ITP_SEC017- Credit Card Use for e-Government
10/03/2023
Security ITP_SEC019- Policy and Procedures for Protecting Commonwealth Electronic Data            
04/07/2023
Security ITP_SEC021- Security Information and Event Management Policy
03/04/2024
Security ITP_SEC023- Technical Security Assessments Policy
09/25/2023
Security ITP_SEC024- IT Security Incident Reporting Policy
04/07/2023
Security ITP_SEC025- Proper Use and Disclosure of Personally Identifiable Information (PII)

04/07/2023
Security ITP_SEC029- Physical Security Policy for IT Resources

09/19/2022
Security ITP_SEC031- Encryption Standards

09/25/2023
Security ITP_SEC032- Enterprise Data Loss Prevention (DLP) Compliance Standards

09/26/2022
Security
ITP_SEC034- Enterprise Firewall Rule Set
06/13/2023
​Security
​ITP-SEC035 Mobile Device Security Policy
02/20/2024
​Security ​ITP_SEC038- Commonwealth Data Center Privileged User Identification and Access Management Policy
​04/25/2023
​SecurityITP-SEC039 Keystone Login and Identity Proofing

04/28/2023
​Security 
​ITP-SEC040 Computing Services Provided by Service Organizations


OPD-SEC040A
OPD_SEC040A word
OPD-SEC040B
OPD-SEC040C
07/18/2023
​Security
ITP-SEC041 Commonwealth IT Resource Patching Policy
(FORMERLY ITP-SYM006)
OPD-SEC041A
OPD-SEC041A word
​12/01/2023
Software ITP SFT000- Software Development Life Cycle (SDLC) Policy

08/15/2018
SoftwareITP_SFT001 Software Licensing​OPD-SFT001A
OPD-SFT001B
OPD-SFT001B_word
OPD-SFT001C
11/27/2023
Software ITP_SFT002 Commonwealth of PA Design Standards
STD-SFT002B
01/04/2024
​SoftwareITP_SFT003- Geospatial Enterprise Service Architecture
02/22/2017
Software ITP_SFT004 Geospatial Information Systems (GIS)
STD-SFT004A
11/19/2021
​Software​ITP_SFT005- Managed File Transfer (MFT)

06/13/2023
Software ITP_SFT006- Internet Browser Policy
STD-SFT006A
04/25/2023
​Software
​ITP-SFT007 - Office Productivity Policy
STD-SFT007A
​05/05/2023
Software ITP SFT008- Enterprise Resource Planning (ERP) Management
01/20/2023
Software ITP SFT009- Application Development05/09/2022
System Management ITP_SYM003- Off-Site Storage for Commonwealth Agencies12/20/2010
System Management ITP_SYM004- Policy for Establishing Alternate Processing Sites for Commonwealth Agencies OPD SYM004A
OPD SYM004B
05/22/2012
System Management ITP_SYM008- Virtualization Policy

02/24/2022
​System Management
ITP_SYM010- Enterprise Change Management Maintenance Policy
OPD SYM010A
​10/19/2021
Telecommunications
ITP_TEL001- Commonwealth Enterprise Telecommunications
OPD_TEL001A
10/03/2023