Search Email Updates Contact Us Residents Business Visitors Government Office of the Mayor NYC.gov always open
Doing Business: IT Security Requirements

DoITT is responsible for publishing Citywide Information Security Policies and Standards which all City agencies, employees, contractors, and vendors are responsible to follow. This page contains those policies which have been classified as public information.

The City of New York takes our responsibility to protect the personally identifiable information that we collect while providing municipal services to the public very seriously. All employees and contractors with access to City information systems are required to read and acknowledge the User Responsibilities policy prior to accessing any City information systems.

Anti-Piracy (in PDF)

AntiVirus (in PDF)

Application Development (in PDF)

Change Management (in PDF)

CISO Role (in PDF)

Citywide Security Accreditation Process (in PDF)

Data Classification (in PDF)

Digital Media Re-use and Disposal Policy (in PDF)

Encryption (in PDF)

Identity Management (in PDF)

Logon Banner (in PDF)

Password (in PDF)

Personnel (in PDF)

Portable Data (in PDF)

Remote Access (in PDF)

Service Provider Policy (in PDF)

User Responsibilities (in PDF)

Vulnerability Management (in PDF)

Wireless Security (in PDF)