← Back to Library
CJIS

CJIS Security Policy v5.9.1

Full Name:
Criminal Justice Information Services (CJIS) Security Policy
Acronym:
CJIS
Type:
US Federal Standard
Organization:
Federal Bureau of Investigation (FBI)
Version:
5.9.1
Year Published:
2022
Popularity:
Low

Overview of CJIS Security Policy

The Criminal Justice Information Services (CJIS) Security Policy, maintained by the FBI's CJIS Division, establishes mandatory security requirements for agencies and organizations accessing Criminal Justice Information (CJI) through FBI systems. Version 5.9.1, published in 2022, defines comprehensive technical and procedural controls protecting the confidentiality, integrity, and availability of criminal justice data including fingerprints, criminal histories, warrants, and law enforcement-sensitive information. Compliance is mandatory for state and local law enforcement, courts, prosecutors, public defenders, and private contractors processing CJI.

The policy addresses the full lifecycle of CJI access from personnel security to physical security, cybersecurity technical controls, incident response, auditing, and training. Organizations accessing FBI systems including the National Crime Information Center (NCIC), Interstate Identification Index (III), and National Fingerprint File must achieve and maintain CJIS compliance to retain access. Non-compliance results in loss of access to critical criminal justice information systems, severely impacting law enforcement operations.

Key CJIS Security Requirements

The CJIS Security Policy organizes requirements into 13 policy areas covering all aspects of information security and personnel security necessary for protecting criminal justice information.

Advanced Authentication (Policy Area 5.6)

CJIS mandates advanced authentication for all users accessing CJI, requiring two-factor authentication combining something you know (password) with something you have (token, smart card, phone) or something you are (biometric). Advanced authentication must meet FBI's technical specifications, including minimum password complexity (at least 8 characters with uppercase, lowercase, numbers, and special characters), password history preventing reuse, maximum password age (90 days for passwords, 2 years for tokens/biometrics), and account lockout after failed authentication attempts.

Organizations must implement advanced authentication for local access, remote access, and mobile device access to CJI. The policy permits various authentication methods including CAC/PIV cards, FIDO tokens, biometrics, and mobile authenticator applications, provided implementations meet technical requirements. Organizations should select methods balancing security with usability for their specific operational contexts.

Encryption (Policy Area 5.10)

The policy requires encryption protecting CJI in transit and at rest. Data in transit over uncontrolled networks must use FIPS 140-2 validated encryption (minimum AES 128-bit, TLS 1.2+). VPN connections, wireless communications, and internet transmissions containing CJI must be encrypted. Data at rest on mobile devices, laptops, removable media, and cloud storage must be encrypted using FIPS-validated algorithms. Organizations should implement full disk encryption for mobile devices and file/database encryption for cloud-hosted CJI.

Auditing and Accountability (Policy Area 5.4)

CJIS requires comprehensive audit logging of all CJI access and security-relevant events. Logs must capture who accessed what information when, including unsuccessful access attempts. Organizations must retain audit logs for one year, protecting them from unauthorized modification or deletion. Automated log review should identify suspicious activities including unusual access patterns, after-hours access, bulk data exports, and privilege escalation attempts. Regular log reviews (at least quarterly) validate logging effectiveness and identify security incidents requiring investigation.

Incident Response (Policy Area 5.12)

Organizations must develop and maintain incident response plans specifically addressing CJI breaches or unauthorized access. Plans must include procedures for incident identification, containment, eradication, recovery, and notification. Critical to CJIS compliance: organizations must notify the FBI CJIS Division and relevant state CJIS Systems Agencies of any actual or suspected CJI security incidents within one hour of discovery. This rapid notification requirement necessitates 24/7 incident detection and escalation capabilities.

Personnel Security (Policy Areas 5.1-5.3)

All personnel with access to CJI must undergo fingerprint-based background checks processed through FBI systems. Organizations must conduct personnel screening before granting CJI access, document screening results, and maintain personnel security records. Background check requirements extend to contractors, vendors, and any personnel with logical or physical access to systems processing CJI. Personnel must receive security awareness training initially and annually, acknowledging security responsibilities and understanding CJI handling requirements.

Compliance and Assessment

State CJIS Systems Agencies (CSAs) oversee compliance within their jurisdictions, conducting regular assessments and audits of agencies and contractors accessing CJI. Organizations must complete CJIS Security Addendums documenting compliance with all policy areas, undergo periodic security assessments (typically annually), and remediate identified deficiencies within specified timeframes. Persistent non-compliance results in access suspension or termination.

Organizations should conduct internal self-assessments quarterly using FBI-provided assessment tools, maintain comprehensive documentation of security controls and procedures, and ensure all technical implementations meet CJIS technical specifications. Many organizations engage external assessors specializing in CJIS compliance to validate readiness before official CSA assessments.

Cloud and Mobile Considerations

CJIS compliance in cloud environments requires careful evaluation of cloud service provider capabilities and shared responsibility models. Cloud providers must undergo FBI-approved audits demonstrating CJIS compliance capabilities. Organizations must ensure cloud implementations satisfy CJIS encryption, access control, auditing, and incident response requirements. Not all cloud services and regions support CJIS compliance—organizations should verify provider capabilities before migrating CJI to cloud platforms.

Mobile access to CJI faces stringent requirements including advanced authentication, device encryption, mobile device management (MDM), remote wipe capabilities, and compliance with mobile device security requirements. Organizations should implement containerization separating CJI from personal data on mobile devices and ensure lost/stolen device procedures include immediate access revocation and remote data deletion.

Frequently Asked Questions

Who must comply with the CJIS Security Policy?

All agencies and organizations accessing FBI CJIS systems must comply, including state/local law enforcement agencies, courts, prosecutors, public defenders, corrections facilities, probation/parole offices, private companies providing services to these agencies (software vendors, cloud providers, managed service providers), and any contractor with access to CJI. Compliance extends throughout the entire chain of custody for criminal justice information, from origination through destruction.

What happens if organizations fail CJIS compliance audits?

Non-compliance consequences vary based on severity and persistence. Minor deficiencies receive corrective action plans requiring remediation within 30-90 days. Significant deficiencies may result in temporary access restrictions pending remediation. Persistent or severe non-compliance results in complete access termination, preventing affected agencies from accessing NCIC, III, and other FBI systems critical to law enforcement operations. Organizations should treat CJIS compliance as mission-critical given operational impacts of access loss.

How does CJIS differ from other federal security frameworks?

CJIS focuses specifically on criminal justice information protection with requirements tailored to law enforcement operational needs. While it shares control categories with frameworks like NIST SP 800-53 and NIST SP 800-171, CJIS includes unique requirements like one-hour incident notification, specific advanced authentication methods, and FBI-approved encryption algorithms. Organizations subject to multiple frameworks should map CJIS controls to other requirements to identify overlaps and gaps requiring additional controls.

Can organizations use cloud services for CJI?

Yes, but cloud providers must demonstrate CJIS compliance through FBI-approved audits. Not all cloud providers offer CJIS-compliant services—organizations must verify provider CJIS certifications before migrating CJI to cloud platforms. Cloud implementations must satisfy all CJIS requirements including encryption, access controls, auditing, and incident notification. Organizations should carefully evaluate shared responsibility models to ensure they implement controls for their portions while providers handle infrastructure-level requirements.

How often does the CJIS Security Policy update?

The FBI updates the CJIS Security Policy annually, publishing new versions typically in June. Updates address emerging threats, technology changes, and lessons learned from security incidents. Organizations must implement new requirements by effective dates specified in policy updates (typically providing 1-2 years for major changes). Organizations should monitor CJIS Division communications for policy updates, participate in state CJIS advisory councils, and plan for continuous compliance program evolution rather than static implementations.