CJIS Security Policy: Encryption, Audits, and Penalties

The CJIS Security Policy is the FBI’s minimum security standard for any organization that accesses, stores, or transmits Criminal Justice Information through FBI systems. It covers encryption, authentication, logging, personnel vetting, training, incident response, and media disposal, and it is enforced through a three-year audit cycle. Falling short can cost an agency access to national crime databases like NCIC and the Interstate Identification Index.1Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

Who Is Bound by the Policy

The reach is broad. Law enforcement agencies at every level, from municipal police through federal bureaus, are the primary group. Non-criminal-justice agencies that run background checks, like licensing boards and social service departments, are covered too. So are private contractors and IT vendors providing cloud hosting, software, or network services to any of those agencies.2Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v5.9.4

Every state has a CJIS Systems Agency (CSA) that sits between the FBI’s CJIS Division and the local organizations using the data. The CSA oversees local implementation, holds compliance documentation, and can terminate an agency’s or vendor’s access to national databases if compliance lapses. Every individual with access, from a dispatcher to a software developer, is personally bound by the protocols.

Core Technical Requirements

Encryption

All Criminal Justice Information must be encrypted at rest and in transit using cryptographic modules validated under FIPS 140-2. Validation means an actual NIST certificate number you can point to, not a vendor’s marketing claim.1Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

Authentication and Access Control

Every user authenticates with credentials meeting the policy’s complexity and management standards. Multi-factor authentication, which the policy calls “advanced authentication,” is required for anyone accessing CJI from outside the agency’s physically secure environment. That covers remote workers, officers in the field, and personnel on mobile devices. Security questions do not satisfy the requirement.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

Logging and Auditing

Systems have to record every instance of CJI access or modification, capturing what happened, when and where, who was involved, and the outcome.2Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v5.9.4 Logs must be retained for at least one year.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0 When Criminal History Record Information is shared with an agency outside the original information exchange agreement, that dissemination gets its own log entry identifying the operator, the authorized receiving agency, the requestor, and the secondary recipient.

Physical Security

Server rooms, data centers, and any space housing equipment that stores or processes CJI must be secured with locks, badge readers, or equivalent controls. Access stays restricted to authorized personnel, and visitor logs are required.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0 Auditors inspect these controls in person.

Mobile Devices

Mobile devices accessing CJI have to run through a centralized Mobile Device Management system that can remotely lock and wipe devices, enforce encryption, detect jailbroken or rooted devices, block unpatched devices from connecting, and automatically wipe after a set number of failed logins. Any jailbroken or rooted device is permanently barred from touching CJI.1Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

Wireless devices also have to apply critical OS patches promptly, encrypt resident CJI, erase cached data at session end, and run malicious code protection. Full-featured operating systems need a personal or agency firewall managed through the MDM. There is one exception: devices that only receive CJI through indirect access, with no ability to run transactions against state or national repositories. The state’s CJIS Systems Officer decides whether a given setup qualifies.

Cloud Storage and Data Sovereignty

Cloud environments are permitted, but a FedRAMP authorization is not a shortcut to CJIS compliance. FedRAMP, StateRAMP, and SOC Type 2 certifications count as additional assurance, not as substitutes for meeting every CJIS requirement independently.2Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v5.9.4 Organizations that assume a FedRAMP Moderate authorization covers the CJIS baseline get caught out.

CJI storage, even encrypted, is only allowed in cloud environments physically located in an Advisory Policy Board member country: the United States, U.S. territories, Indian Tribes, or Canada. The data center also has to be under the legal authority of an agency from one of those jurisdictions. International exchanges under specific agreements, such as Preventing and Combating Serious Crime agreements, are a narrow exception.

Training and Personnel Vetting

Training must be completed before access is granted, with refresher training every year afterward. If a security event occurs, anyone involved must receive additional training within 30 days. Training records are kept for at least three years.1Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

The policy defines four role-based tiers, each building on the previous one:

  • Level 1 covers personnel with unescorted physical access to facilities but no access to CJI systems, such as janitorial and maintenance staff.
  • Level 2 is for standard users with non-administrative access to systems that process or store CJI. Most agency employees sit here. It adds password security, encryption, and malicious code protection.
  • Level 3 is for system and network administrators with privileged access, adding patch management, data backup, and current policy changes.
  • Level 4 is for information security officers and security leadership, covering audit findings, the Local Agency Security Officer role, and organizational security oversight.

Every individual with access to CJI has to clear a fingerprint-based background check against national databases. Anyone with a disqualifying criminal history is denied access.4Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v5.9.5

Private contractors carry an extra requirement: signing the CJIS Security Addendum before doing any work involving CJI systems. The addendum binds the contractor to the same security standards as the hiring agency. Agencies get the current version from their state’s CSA. Auditors will ask for signed copies, and a missing document can itself become a finding.

Media Sanitization

When hardware or documents containing CJI are retired, agencies cannot just discard them. Digital media has to be overwritten at least three times or degaussed before disposal or reuse. Inoperable media that cannot be overwritten must be physically destroyed by shredding or cutting.2Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v5.9.4 Physical documents must be crosscut shredded or incinerated.

Incident Reporting

Suspected security incidents have to be reported no later than one hour after discovery.4Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v5.9.5 The clock starts when someone identifies a potential breach, not when it is confirmed. Confirmed incidents are then reported to the CJIS Systems Officer, State Identification Bureau Chief, or relevant Interface Agency Official.

Every agency needs a written incident response plan reviewed and approved by executive leadership each year. The plan has to define what counts as a reportable incident, designate personnel responsible for handling it, include procedures for sharing incident information, and set metrics for measuring response capability.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0 For breaches involving personally identifiable information, the plan also has to include a process to assess harm to affected individuals and decide whether to notify them.

The plan has to be distributed to everyone with incident-handling responsibilities, updated when systems or organizational structures change, and protected from unauthorized disclosure.

The Triennial Audit

The FBI’s CJIS Audit Unit audits every CSA and state repository on a three-year cycle, and state CSAs audit local agencies within their jurisdiction on their own schedule.5FBI.gov. Auditors Safeguard Integrity of CJIS Systems

The audit manager contacts the agency’s CJIS Systems Officer or Information Security Officer about six months before the onsite visit. The agency then works through a pre-audit questionnaire requesting management control agreements, signed Security Addendums, personnel sanctions policies, training records, technical audit reports, network infrastructure descriptions, and details on encryption, authentication, and logging.6FBI.gov. Information Technology Security Audit

Onsite, auditors interview key personnel, review the documentation collected earlier, inspect server rooms and terminals, and confirm that access controls and encryption are actually working. A standard onsite visit runs four to eight hours a day. Agencies get immediate feedback at an exit briefing, and the written report with corrective action recommendations arrives about four months later. The report also goes to the CJIS Advisory Policy Board’s Compliance Evaluation Subcommittee or the Compact Council’s Sanctions Committee. If deficiencies are found, the agency submits a corrective action plan, and the audit unit tracks the recommendations until they are complete.

What Non-Compliance Costs

The Compact Council’s Sanctions Committee reviews FBI audit results and the agency’s response using 28 CFR Part 907 as its framework.7FBI.gov. Sanctions Process Information If the response is insufficient, the offending agency goes on probationary status and the head of the relevant state agency is notified. Continued non-compliance escalates to the state’s oversight official, with a warning that access to the Interstate Identification Index may be suspended. If deficiencies still are not fixed, the Compact Council can direct the FBI to suspend the agency’s noncriminal justice access entirely.8eCFR. 28 CFR Part 907 – Compact Council Procedures for Compliant Conduct and Responsible Use of the III System For criminal justice agencies, the FBI Director can take separate action consistent with the Council’s recommendations.

At the individual level, agencies have to run a formal sanctions process for employees who violate security policies. When an employee sanction is initiated, information security personnel, personnel security staff, and system administrators must be notified within 24 hours, with the individual and reason identified.1Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0 The policy recommends consulting general counsel before initiating sanctions.

For a law enforcement agency, losing database access means losing the ability to run warrant checks, verify criminal histories, and use the systems officers rely on daily. The graduated process gives agencies multiple chances to correct course, but treating early findings as routine paperwork is how agencies end up explaining a suspension to their oversight board.