Who Is Responsible for NCIC System Security? FBI, State, and Local Roles

Responsibility for National Crime Information Center security is shared across a layered chain: the FBI’s Criminal Justice Information Services Division manages the system and writes the rules, each state’s CJIS Systems Agency enforces them within its borders, local departments secure their own environments and users, every individual with a login is personally accountable for how they use it, and any private contractor or cloud provider that touches the data is bound by the same standards. A failure at any level can compromise the whole system, which is why the duties are spelled out in detail and the penalties for violations reach from lost access to federal prison.

The FBI’s CJIS Division at the Top

Federal law gives the Attorney General authority to collect, preserve, and exchange criminal identification records with authorized federal, state, tribal, and local officials.1Office of the Law Revision Counsel. 28 U.S. Code 534 – Acquisition, Preservation, and Exchange of Identification Records and Information The FBI exercises that authority through its Criminal Justice Information Services Division, which runs NCIC.2eCFR. 28 CFR Part 20 – Criminal Justice Information Systems The CJIS Division operates the central database, maintains the telecommunications network connecting thousands of agencies, and sets the security standards everyone else must follow.

NCIC is not just a database. Federal regulations define it as the whole computerized system, including the telecommunications lines and message-switching facilities linking local, state, tribal, federal, and international criminal justice agencies.2eCFR. 28 CFR Part 20 – Criminal Justice Information Systems That broad definition matters. Security duties don’t stop at the central server; they run out to every connection point in the network.

The rulebook that binds every participant is the CJIS Security Policy. Version 6.0 was released in December 2024, and it governs how criminal justice information must be protected from the moment it is created until it is disposed of.3FBI. Criminal Justice Information Services (CJIS) Security Policy Version 6.0 Password requirements, encryption strength, background checks, media disposal, audits, incident reporting: it is all in that document, and it applies to every entity that accesses or stores the data.

State CJIS Systems Agencies

Each state has a designated CJIS Systems Agency, or CSA, that acts as the bridge between the FBI’s CJIS Division and the local agencies within its borders. The CSA must establish and run an information security program across its entire user community, down to the local level.4FBI. Criminal Justice Information Services (CJIS) Security Policy Version 5.9.5 A CSA can also require stricter protections than the federal baseline as long as the decision is documented.

The head of each CSA appoints a CJIS Systems Officer, or CSO, to handle day-to-day administration of the network within the state. That job cannot be outsourced. The CSO sets standards for personnel selection and separation, enforces operating procedures, ensures compliance with policies approved by the Advisory Policy Board, and appoints a state-level Information Security Officer.4FBI. Criminal Justice Information Services (CJIS) Security Policy Version 5.9.5 When something goes wrong at the state level, that is the officer who answers for it.

CSAs also audit every criminal justice and noncriminal justice agency with direct access to the state system at least once every three years, and they may conduct unannounced security inspections of contractor facilities.4FBI. Criminal Justice Information Services (CJIS) Security Policy Version 5.9.5

Local Agencies and Control Terminal Agencies

Local police departments and other agencies connected to NCIC secure their own environments. That means controlling physical access to the rooms where NCIC terminals and network equipment sit, using measures like restricted entry points and alarm systems, and defending the local network against cyber threats.

Some agencies carry a heavier load. Federal regulations define a Control Terminal Agency as an authorized criminal justice agency with direct access to the NCIC telecommunications network that provides statewide or equivalent service to its users.2eCFR. 28 CFR Part 20 – Criminal Justice Information Systems These agencies are the conduit through which other local users reach the system, so a breach at that level can cascade outward.

Local agencies also manage which of their own staff can access NCIC and make sure those users follow the rules. Supervisors watch for unauthorized queries, and the department must have a process to revoke access immediately when someone leaves or changes roles.

Individual Users

Every person who logs in to an NCIC-connected system is personally accountable for what they do with it. The CJIS Security Policy requires multi-factor authentication for both privileged and non-privileged accounts, meaning users need at least two of: something they know (a PIN), something they have (a hardware token or phone), or something they are (a fingerprint).4FBI. Criminal Justice Information Services (CJIS) Security Policy Version 5.9.5 That control is designated Priority 1, treated as non-negotiable.

Users may query NCIC only for legitimate criminal justice purposes. Federal regulations define those as activities related to detecting, apprehending, detaining, prosecuting, adjudicating, or supervising accused persons or criminal offenders, including criminal identification activities.2eCFR. 28 CFR Part 20 – Criminal Justice Information Systems Running a name to check on an ex-spouse, look up a neighbor, or help a friend with a background check falls outside that definition and can lead to criminal prosecution.

Anyone with access must pass a fingerprint-based background check and complete security awareness training within six months of gaining access, and then again every two years. Records received from NCIC may be used only for the purpose for which they were requested; a fresh record must be pulled when needed for a different authorized use.5eCFR. 28 CFR 20.33 – Dissemination of Criminal History Record Information

Private Contractors and Cloud Providers

Many agencies rely on private software vendors, IT contractors, and cloud hosting companies. Those third parties are held to the same rules. Any private contractor performing criminal justice functions must sign the CJIS Security Addendum, a uniform agreement approved by the Attorney General that authorizes access to criminal history information, limits how the contractor may use it, and provides for sanctions if the terms are violated.5eCFR. 28 CFR 20.33 – Dissemination of Criminal History Record Information

Contractors must meet the same training and certification standards as government agencies performing similar functions and are subject to the same audit reviews.4FBI. Criminal Justice Information Services (CJIS) Security Policy Version 5.9.5 Cloud providers face extra constraints. Criminal justice information can be stored only in cloud environments physically located in the United States, U.S. territories, Indian Tribes, or Canada, and only under the legal authority of an Advisory Policy Board member agency. Any provider employee who can access unencrypted criminal justice data must undergo the same fingerprint-based background check as law enforcement personnel. Providers whose staff never see unencrypted data because the agency holds all encryption keys may be exempt from that screening.

How Responsibility Gets Enforced

The FBI’s CJIS Audit Unit reviews all CJIS Systems Agencies and data repositories on a three-year cycle. On-site auditors interview key personnel, run data quality reviews, and tour facilities to evaluate physical security.6FBI. Auditors Safeguard Integrity of CJIS Systems State CSAs run parallel audits of their own user community on the same three-year cycle.4FBI. Criminal Justice Information Services (CJIS) Security Policy Version 5.9.5 Non-compliance with the CJIS Security Policy can bring administrative sanctions up to and including termination of an agency’s access to the system.

When an incident is suspected, personnel must report it immediately, and no later than one hour after discovery.4FBI. Criminal Justice Information Services (CJIS) Security Policy Version 5.9.5 The state-level Information Security Officer establishes the incident response and reporting procedure, investigates confirmed incidents, and escalates major ones to the FBI CJIS Division’s Information Security Officer.

Individuals who misuse NCIC face criminal exposure. The Computer Fraud and Abuse Act makes it a crime to intentionally access a nonpublic government computer without authorization or to exceed authorized access. A first offense carries up to one year in prison, and a second conviction under the same statute raises the maximum to ten years.7Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers If the unauthorized access was for commercial advantage, private financial gain, or in furtherance of another crime, the penalty rises to up to five years even on a first offense.

The Privacy Act adds a second layer. A government employee who knowingly and willfully discloses individually identifiable records to someone not entitled to receive them is guilty of a misdemeanor and faces a fine of up to $5,000.8Office of the Law Revision Counsel. 5 U.S. Code 552a – Records Maintained on Individuals Officers prosecuted for running personal queries or selling information have learned that curiosity is not a defense once the access logs show a pattern.

The dissemination rules extend the consequences past the individual. Records obtained through NCIC may be shared only with authorized recipients, and sharing them outside the receiving agency can result in cancellation of that agency’s access to the system entirely.5eCFR. 28 CFR 20.33 – Dissemination of Criminal History Record Information One officer’s misconduct can cost an entire department the tool its colleagues rely on every shift.