Back to Blog
Insights9 min read

NY State ITS Policy Compliance: What to Look for in a Third-Party Security Assessor

A

Alexander Sverdlov

Security Analyst

7/20/2026
NY State ITS Policy Compliance: What to Look for in a Third-Party Security Assessor

If your organization runs New York State systems, handles state data, or bids on state contracts, you eventually run into the NYS Office of Information Technology Services (ITS) security policy set. These are the P-series policies and standards that govern how state entities and their partners protect information: access control, encryption, incident management, and more. I have spent since 2013 running security assessments against exactly this kind of government control framework across 14 countries, and the mechanics of proving compliance to a state authority are consistent everywhere. What changes is the specific policy language, and New York's is detailed enough that a generic auditor will miss things.

This is a practical guide to what NYS ITS compliance actually requires, and how to choose a third-party assessor who understands the state context rather than one who will run a generic checklist and hand you a report that does not survive scrutiny. I will keep it concrete and skip the fear-selling.

What the NYS ITS Policies Cover

The ITS information security policies and standards translate broad security principles into requirements that state entities and their vendors must meet. The policy set is anchored on recognized control frameworks, so if you have worked with NIST SP 800-53 or ISO 27001 the structure will feel familiar. In practice the areas an assessor will focus on include:

What this guide covers: What the NYS ITS Policies Cover, Why Independence Matters for State Compliance, How to Choose a NYS ITS Assess
  • Access control - least privilege, unique accounts, multi-factor authentication, and disciplined account lifecycle management.
  • Encryption and data protection - protecting sensitive information in transit and at rest, with proper key management.
  • Incident management - documented, tested response procedures and defined reporting obligations.
  • Configuration and change management - hardened baselines and controlled change on systems that handle state data.
  • Risk management and continuous monitoring - ongoing identification and remediation of weaknesses rather than a once-a-year look.
  • Third-party and vendor risk - because the obligations flow downstream to anyone who touches the data.

The important nuance is that ITS expectations are policy-specific. An assessor who knows NIST but has never read the actual NYS ITS policies will map your controls to the wrong requirements and give you a false sense of coverage. State-specific fluency is the whole point of hiring a specialist.

Why Independence Matters for State Compliance

You can self-assess, and you should, continuously. But when a state authority, a procurement office, or a prime contractor wants assurance, they generally want it from an independent party with no incentive to hide problems. A qualified third-party assessor gives you:

Checklist: Why Independence Matters for State Compliance
  • Evidence that holds up. Audit-ready artifacts that map each ITS policy requirement to a specific control test and the evidence behind it, structured so they survive review and public-records requests.
  • Real testing, not interviews alone. Penetration testing, configuration review, and vulnerability assessment that demonstrate controls work under realistic conditions.
  • Process validation. Incident response drills, change-management review, and vendor risk evaluation, because paper procedures fail when they are never exercised.
  • A prioritized remediation roadmap. Findings ranked by real risk, with owners, deadlines, and re-test criteria, so you fix what matters first.

A useful assessment is measured by what you can fix afterward, not by the thickness of the binder.

How to Choose a NYS ITS Assessor

Ignore star charts and self-declared rankings, including any vendor that puts itself at the top of its own comparison table. Evaluate assessors on verifiable substance:

Checklist: How to Choose a NYS ITS Assessor
What to checkWhat good looks likeWarning sign
State-specific experienceDemonstrated work against NYS ITS policies, not just "government"Generic framework mapping with no NY specifics
Who does the testingNamed, certified testers (CISSP, CISA, and similar) on your engagementSenior names in the pitch, juniors on the job
MethodologyWritten test plans showing how each control is exercisedQuestionnaire-only "assessment"
DeliverablesExecutive summary plus raw evidence and reproduction stepsA rating sheet with no supporting logs
ReferencesRedacted sample reports and reference calls you can actually makeOnly a logo wall

Ask for anonymized sample deliverables and at least a couple of reference calls before you sign anything. Certifications and testing experience across frameworks such as ISO 27001 and NIST are a good sign, but only if paired with genuine familiarity with the NYS ITS policy language. Our own IT security audit and ISO 27001 readiness work is built around exactly this kind of policy-to-evidence mapping.

A Step-by-Step Selection and Preparation Path

Here is the sequence I recommend to any state entity or contractor preparing for an ITS-facing assessment.

1. Define scope precisely

Catalog the applicable ITS policies, the in-scope systems (citizen-facing portals, internal applications, vendor integrations), and the real data flows. An unclear boundary is the most common cause of a painful, drawn-out assessment.

2. Run an internal gap analysis first

Score each in-scope control as implemented, partially implemented, or not implemented, and remediate the high-risk gaps before an external assessor arrives. Missing MFA, flat networks around sensitive data, and unmonitored logging are the findings that draw the most scrutiny. Closing them quietly beforehand is far cheaper than explaining them later.

3. Issue a specific request for proposal

Require evidence of recent NYS ITS work, resumes of the lead testers, and sample executive summaries alongside raw logs. Vague proposals produce vague assessments.

4. Vet credentials and independence

Confirm relevant certifications, demonstrated NYS experience, and that the assessor has no conflict of interest with the tools or products they may recommend.

5. Run a scoped pilot

Start with a single domain, such as network segmentation or access control, to evaluate the assessor's communication, clarity, and adherence to timelines before committing to full scope.

6. Negotiate sensible terms

Agree clear deliverable timelines, a defined response window for critical findings, secure handling and destruction of any sensitive data, and a prohibition on undisclosed subcontractors.

7. Execute, remediate, and validate

Support the assessment with just-in-time access and a responsive point of contact. Then assign owners and deadlines to findings, remediate, and re-test the high-risk items so you can document closure evidence for your submission.

Common Pitfalls to Avoid

  • Generic, one-size-fits-all scoping. Reject templates that ignore the specific NYS ITS policies you are accountable for.
  • Checkbox audits. Controls must operate under realistic attack simulation, not merely exist on paper. This is where genuine penetration testing separates a real assessment from a paperwork exercise.
  • Ignoring vendor risk. ITS obligations extend to third parties. Cascade the requirements downstream and verify them; do not assume.
  • Skipping validation. Unverified remediation leaves you exposed on audit day and undermines the entire exercise.
  • Relying on scanners alone. Automated scans miss business logic, process gaps, and the human factor. Pair them with manual testing and a proper vulnerability assessment.

Staying Compliant After the Assessment

An assessment result is a snapshot. Controls drift, staff turn over, and new systems come online. State entities that never scramble at audit time treat readiness as continuous:

14 countries: If your organization runs New York State systems, handles state data, or bids on state contracts
  • Continuous monitoring. Use SIEM and alerting to catch policy exceptions and anomalous access as they happen.
  • Periodic policy refresh. Review procedures on a schedule aligned with new ITS bulletins and regulatory updates, not just before the next audit.
  • Ongoing awareness training. Run phishing simulations and tabletop incident response drills regularly, because the human layer degrades fastest.
  • Vendor assurance. Re-verify critical suppliers against the same standards you hold yourself to.
  • Metrics that matter. Track mean time to detect, mean time to remediate, and control maturity so you can show trend, not just a point-in-time result.

For organizations without a full-time security leader to own this work between assessments, an outsourced or virtual CISO can carry the continuous-readiness load and keep you audit-ready year round.

24 hours: Preparing for a NYS ITS assessment? I help state entities and contractors scope, remediate

Frequently Asked Questions

Who has to comply with NYS ITS security policies?

New York State entities that operate state systems or handle state information, and generally the vendors and contractors who provide services that touch that data. If you are bidding on or delivering a state contract, expect the obligations to flow to you through the agreement, and expect to have to demonstrate compliance.

What the NYS ITS Policies Cover - key points

How do the ITS policies relate to NIST and ISO 27001?

The ITS policy set is anchored on recognized security control principles, so it maps closely to frameworks like NIST SP 800-53 and ISO 27001. That overlap means a single well-built body of evidence can often support ITS requirements and another framework at the same time. The catch is that the ITS policies have state-specific language and requirements a generic mapping will miss.

Can we self-assess, or do we need a third party?

Self-assessment is valuable and should be continuous, but when a state authority or a prime contractor wants assurance they usually want it from an independent third party with no incentive to hide problems. Independence is what makes the result credible externally.

What is the most common reason organizations fail an assessment?

Treating documentation as evidence. A policy that says a control exists is not proof it works. The organizations that pass cleanly can show each control configured, enforced, logged, and tested, with artifacts behind every claim.

How should we choose between assessors?

Judge on verifiable substance, not marketing. Look for demonstrated NYS ITS experience, named certified testers on your engagement, a written testing methodology, deliverables that include raw evidence, and real references you can call. Be skeptical of anyone who ranks themselves at the top of their own comparison chart or promises a guaranteed pass before seeing your environment.

Preparing for a NYS ITS assessment? I help state entities and contractors scope, remediate, and prove compliance with evidence that survives scrutiny, drawing on 200+ assessments across 14 countries. Book a free strategy call and get a fixed-price proposal within 24 hours.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

NYS ITS Policy Compliance: Choosing a Security Assessor