AuditXYZ

Compliance Framework

FBI Criminal Justice Information Services Security Policy (CJIS)

The CJIS Security Policy governs access to FBI criminal justice data. This guide covers authentication, encryption, personnel security, and compliance requirements for agencies and technology vendors.

$30,000–$250,0003–9 monthsAudit Requiredv5.9.5 (2024)
Issuing BodyFederal Bureau of Investigation (FBI) Criminal Justice Information Services Division
First Published1998-01-01
Latest Versionv5.9.5 (2024)
Typical Cost$30,000–$250,000
Typical Timeline3–9 months
Audit RequiredYes
Audit FrequencyFBI CJIS conducts triennial audits of state-level compliance. State-level audits of local agencies and contractors vary by state.
Geographyunited-states

CJIS Security Policy: Criminal Justice Information Security Guide

The FBI Criminal Justice Information Services (CJIS) Security Policy establishes the minimum security requirements for access to FBI CJIS systems and criminal justice information (CJI). Covering everything from the National Crime Information Center (NCIC) to fingerprint databases and the National Instant Criminal Background Check System (NICS), the CJIS Security Policy protects some of the most sensitive law enforcement data in the United States. For any technology company whose products touch law enforcement workflows, CJIS compliance is a hard market requirement.

What CJIS Is and Who Issues It

The FBI's Criminal Justice Information Services Division, headquartered in Clarksburg, West Virginia, is the largest division of the FBI and serves as a high-tech hub for the criminal justice community. CJIS manages the criminal justice information systems that law enforcement agencies across the country rely on daily — including the National Crime Information Center (NCIC), the National Fingerprint File, the Interstate Identification Index, the National Instant Criminal Background Check System (NICS), the Law Enforcement Enterprise Portal (LEEP), and numerous other national databases.

The CJIS Security Policy was first established in 1998 and has been continuously updated. Version 5.9.5, current as of 2024, reflects ongoing updates to address cloud computing, mobile device security, and modern authentication requirements. The policy is developed collaboratively by the CJIS Advisory Policy Board (APB), which includes representatives from federal, state, local, and tribal law enforcement agencies.

The governance model is notable for its federated structure. The FBI CJIS Division sets minimum standards through the Security Policy. Each state's CJIS Systems Agency (CSA) — typically the state police or department of public safety — is responsible for implementing and enforcing the policy within its jurisdiction and for auditing local agencies and contractors. This means CJIS compliance requirements can vary in implementation detail by state, though the federal minimums apply universally.

Who Needs CJIS Compliance

CJIS compliance is required for all criminal justice agencies accessing FBI CJIS systems, including federal, state, local, and tribal law enforcement agencies, prosecutors' offices, courts, and corrections departments. The policy applies to any person — whether a government employee or private contractor — who has access to CJI.

The scope extends meaningfully to private-sector technology vendors. Any company providing services that involve access to CJI must comply with the CJIS Security Policy. This broad scope captures cloud service providers hosting law enforcement data, records management system (RMS) vendors, computer-aided dispatch (CAD) vendors, body-worn camera vendors, jail management system providers, mobile data terminal vendors, IT managed service providers serving law enforcement, and analysis platform providers accessing criminal justice data.

Technology vendors must execute CJIS Security Addenda with the criminal justice agencies they serve, contractually committing to compliance with the Security Policy. The vendor is responsible for ensuring its employees who have access to CJI have completed required background investigations and training.

Key Requirements: The 13 Policy Areas

The CJIS Security Policy defines 13 policy areas covering the complete information security lifecycle for CJI.

Policy Area 1: Information Exchange Agreements requires formal written agreements between agencies (Management Control Agreements) and between agencies and contractors (Security Addenda) that establish compliance obligations and enforcement rights.

Policy Area 2: Security Awareness Training requires all personnel with access to CJI to complete CJIS Security Awareness Training within six months of hire and every two years thereafter. Training covers the sensitivity of CJI, access control requirements, and proper handling procedures.

Policy Area 3: Incident Response requires agencies and vendors to document and report security incidents, including unauthorized access to CJI systems and breaches of CJI. Incident reporting obligations extend to the state CJIS Systems Agency.

Policy Area 4: Auditing and Accountability is one of the most technically demanding areas. It requires comprehensive logging of all access to CJI systems — who accessed what data, when, from where. Logs must be retained and available for audit. This requirement has significant technical implications for cloud-hosted systems.

Policy Area 5: Access Control requires access to CJI to be limited based on need-to-know and least privilege principles. User accounts must be uniquely identified. Shared accounts are prohibited. Regular access reviews are required.

Policy Area 6: Identification and Authentication is among the most impactful for technology vendors. CJIS requires Advanced Authentication (essentially multi-factor authentication) at the point of access to CJI. The authentication must meet specific requirements — something you know (password) plus something you have (hardware token, smart card, or mobile authenticator). SMS-based OTP does not satisfy CJIS Advanced Authentication requirements in many interpretations. This requirement has driven significant product redesigns by law enforcement technology vendors.

Policy Area 7: Configuration Management requires baseline configurations, change management procedures, and regular review of system configurations to ensure unauthorized changes are detected.

Policy Area 8: Media Protection covers protection of physical and electronic media containing CJI, including requirements for secure disposal (physical destruction or NIST-compliant data sanitization) and controls on removable media.

Policy Area 9: Physical Protection requires physical security controls for facilities and systems that store or process CJI, including access controls, visitor management, and protection of unattended workstations.

Policy Area 10: System and Communications Protection requires FIPS 140-2 validated encryption for all CJI at rest and in transit. This is a critical requirement for cloud vendors — all data storage and transmission must use FIPS-validated cryptographic modules, not merely strong encryption. This distinction matters: AES-256 is strong, but it must be implemented in a FIPS 140-2 validated module to satisfy CJIS requirements.

Policy Area 11: Formal Audits establishes the audit program — state CSAs conduct triennial audits of local agencies, and the FBI conducts triennial audits of state CSAs. Vendors are subject to audit through their Management Control Agreements.

Policy Area 12: Personnel Security requires fingerprint-based background investigations for all personnel with access to CJI, including vendor employees. The investigation must be completed before access is granted. This has significant operational implications for vendors that need to deploy staff to law enforcement facilities or access CJI remotely.

Policy Area 13: Mobile Devices addresses the significant security challenges of mobile law enforcement technology. Mobile devices accessing CJI must meet specific encryption, authentication, and management requirements. Personally-owned devices (BYOD) face additional restrictions.

The Assessment and Compliance Process

CJIS compliance does not involve a single certification — it is an ongoing compliance obligation enforced through a federated audit structure.

Technology vendors seeking to serve law enforcement begin by identifying their CJIS obligations based on the type of access to CJI their product requires. They then implement required technical controls (FIPS encryption, Advanced Authentication, audit logging) and administrative controls (security policies, background investigation procedures, training programs).

Vendors must negotiate CJIS Security Addenda with each criminal justice agency they serve. The Security Addendum is a standardized contract (developed by the FBI CJIS Advisory Policy Board) in which the vendor commits to CJIS Security Policy compliance and grants audit rights to the agency and state CSA.

State-level audits of vendors vary by state. Some states conduct regular audits of vendors; others rely primarily on agency-level controls. Vendors should understand the audit expectations in each state where they have law enforcement customers.

Cloud service providers seeking CJIS compliance often leverage FedRAMP authorized infrastructure as a foundation — FedRAMP authorization addresses many CJIS technical requirements, reducing incremental compliance costs for the cloud infrastructure layer.

Costs and Timeline

Organization TypeEstimated CostTimeline
Criminal justice agency (baseline)$30K–$100K3–6 months
Small technology vendor (limited CJI access)$50K–$120K4–7 months
Large technology vendor (cloud-hosted CJI)$120K–$250K6–9 months
FIPS-compliant infrastructure build-out$50K–$150K+Variable

CJIS maps to NIST SP 800-53 at approximately 60% overlap. The CJIS Security Policy draws heavily on NIST guidelines, and organizations familiar with NIST 800-53 will find CJIS requirements conceptually familiar while noting the law-enforcement-specific additions (background investigations, CJI handling procedures, state audit structures).

FedRAMP at approximately 50% overlap provides a strong foundation for CJIS-compliant cloud infrastructure. FedRAMP Moderate authorization demonstrates a broad security control baseline that satisfies many CJIS technical requirements. Several cloud providers have obtained both FedRAMP authorization and CJIS compliance, offering "CJIS-compliant cloud" offerings to law enforcement. ISO 27001 overlaps at approximately 45% — it provides relevant information security management structure but lacks the law-enforcement-specific requirements of CJIS.

For government-focused vendors navigating multiple federal compliance requirements, see our government compliance guide for how CJIS, FedRAMP, and DFARS interact.

How Automation Helps

CJIS compliance generates ongoing evidence requirements — audit logs, access reviews, training records, background investigation documentation, and incident reports must be maintained and available on short notice when state auditors request them.

LowerPlane supports CJIS as part of its 50+ framework compliance library. Its continuous evidence collection is particularly valuable for Policy Area 4 (auditing and accountability) and Policy Area 5 (access control), where continuous log management and access review documentation are required. Starting at $4,000 per year with a free tier available. AuditXYZ rated LowerPlane 9.4/10.

Frequently Asked Questions

What counts as "access to CJI" for CJIS compliance purposes? Access to CJI means any access — direct query, indirect exposure, or administrative access — to data sourced from CJIS systems. This includes administrators of systems that store CJI, even if they don't personally query criminal records. Cloud engineers with the ability to access storage containing CJI, IT support staff who can access law enforcement workstations, and data center personnel with physical access to servers hosting CJI may all be in scope.

Does FIPS 140-2 validation still apply, or is FIPS 140-3 now required? As of 2024, FIPS 140-2 remains acceptable, and FIPS 140-3 (the 2019 revision) modules are also acceptable. NIST is transitioning to FIPS 140-3 as the current standard, but 140-2 validated modules remain valid for use. Vendors should ensure their encryption implementations use modules validated under either standard and plan for eventual transition to 140-3.

Can we use a FIPS-compliant cloud platform (like AWS GovCloud) to satisfy CJIS encryption requirements? Using a FIPS-compliant cloud platform satisfies the infrastructure-level encryption requirements. However, application-level encryption — how the application itself stores and transmits data before it reaches the cloud storage layer — must also use FIPS-validated implementations. Additionally, CJIS requirements beyond encryption (background investigations, advanced authentication, audit logging, training) must be addressed by the vendor's own compliance program regardless of the cloud platform used.

What is the CJIS Security Addendum and who must sign it? The CJIS Security Addendum is a standardized agreement developed by the FBI CJIS Advisory Policy Board that private entities must execute with each criminal justice agency they serve. It commits the vendor to CJIS Security Policy compliance, grants audit rights, establishes breach notification obligations, and requires background investigations for vendor personnel with CJI access. The Addendum must be signed before the vendor's personnel can access CJI.

Are there specific requirements for mobile applications used in law enforcement? Yes. Policy Area 13 addresses mobile devices specifically. Mobile apps accessing CJI must implement device encryption, remote wipe capability, screen lock with timeout, and specific authentication requirements. The handling of personally-owned devices (BYOD) in law enforcement contexts is particularly restricted — CJI accessed on personally-owned devices must be protected through containerization or other approved mechanisms.

Request a CJIS consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

NIST SP 800 53Medium60%
FedRAMPMedium50%
ISO 27001Low45%

Related frameworks

Get matched with a CJIS auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.