FBI CJIS Security Policy
Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Control
Enforce role-based access, least privilege, separation of duties, and session controls for access to criminal justice information.
- Role catalog
- Access review report
- Session timeout configuration
- Standing administrator accounts
- No separation of duties for evidence review
- Session timeouts too long
Account Management
Create, modify, disable, and remove accounts based on documented authorization and review accounts at defined intervals.
- Joiner-mover-leaver workflow
- Quarterly access review evidence
- Disabled account list
- Dormant accounts not disabled
- Movers retain prior access
- Reviews not signed off by data owner
Audit
Generate, protect, and retain audit records sufficient to reconstruct events and support investigations.
- Logged event catalog
- SIEM retention configuration
- Audit review evidence
- Privileged actions not logged
- Retention shorter than one year
- No documented review cadence
Awareness and Training
Provide CJIS security awareness training to all personnel with access to criminal justice information at hire and at least every two years.
- CJIS training plan
- Learner transcripts
- Quiz results
- Contractors not enrolled
- No level-appropriate content for elevated roles
- Refresh cycle exceeded
Compliance
Subject systems and processes to formal CJIS audits at least every three years and remediate findings.
- Triennial audit report
- CAP tracker
- Closure evidence
- Findings open beyond agreed timelines
- No evidence library
- Reauditing scope reduced without justification
Configuration Management
Establish and maintain baseline configurations for systems handling criminal justice information and control changes through a documented process.
- CIS or DISA STIG baseline
- Change tickets
- Asset inventory
- Baselines not benchmarked
- Emergency changes bypass review
- Inventory missing mobile devices
Where cloud services process criminal justice information, ensure CJIS-specific controls are inherited or implemented and evidenced by the provider.
- Provider CJIS attestation
- Shared responsibility matrix
- Customer-managed control evidence
- No CJIS-specific attestation
- Customer responsibilities not assigned
- FedRAMP scope mismatch
Governance and Agreements
Establish information exchange agreements outlining roles, responsibilities and data ownership for CJI
- Information exchange agreement
- Connected agency register
- Authorisation records
- Annual review
- Agreements stale
- Register incomplete
- Review skipped
Conduct regular personnel training on CJI risks, handling and incident reporting
- Awareness training curriculum
- Completion records
- Role-based modules
- Annual refresh evidence
- Role-based modules absent
- Refresh skipped
- Completion gaps
Screen and vet personnel with access to CJI through background checks
- Background check policy
- Fingerprint records
- Adjudication log
- Reinvestigation schedule
- Reinvestigation skipped
- Adjudication weak
- Records incomplete
Identification and Authentication
Uniquely identify users and use advanced authentication for access to criminal justice information from non-secure locations.
- MFA enforcement report
- Identity proofing records
- Password policy
- SMS used as second factor
- Shared accounts for kiosk use
- No re-proofing after role change
Incident Response
Implement an incident response capability covering detection, analysis, containment, eradication, recovery, and reporting to the CJIS Systems Officer.
- Incident response plan
- Tabletop exercise report
- CSO notification log
- No tabletop in last 12 months
- Reporting timelines not met
- Forensic preservation steps missing
Notify the CJIS Systems Officer of incidents involving criminal justice information within required timeframes.
- CSO notification record
- Incident report template
- Post-incident review
- Notifications informal and undated
- Reporting template missing required fields
- No CSA coordination evidence
Information Exchange
Establish written agreements that govern the exchange of criminal justice information between agencies and service providers.
- Signed CJIS information exchange agreement
- Management control agreement
- Service provider security addendum
- Agreements not refreshed on contract changes
- Missing CJIS Security Addendum for vendors
- No central register of agreements
Media Protection
Protect digital and physical media containing criminal justice information from unauthorized access and securely sanitize or destroy media at end of life.
- Media handling SOP
- Sanitization certificates
- Chain of custody log
- No certificate of destruction
- Reuse of media across classifications
- Couriers not vetted
Mobile
Apply additional controls for mobile devices accessing criminal justice information, including device management, encryption, and remote wipe.
- MDM policy and enrolment report
- Encryption attestation
- Wipe procedure
- BYOD devices unmanaged
- No remote wipe
- Geofencing not applied to in-vehicle MDTs
Personnel
Conduct fingerprint-based background checks and approval prior to granting unescorted access to criminal justice information.
- Fingerprint submission records
- Adjudication memo
- Termination access removal log
- Background checks not refreshed for high-risk roles
- Contractor checks performed by vendor only
- Access removed late on separation
Physical Security
Restrict physical access to systems and facilities that process criminal justice information to authorized personnel and protect against environmental hazards.
- Access list
- Visitor logs
- Environmental monitoring reports
- Tailgating not addressed
- Visitor logs paper-only and incomplete
- No fire suppression in equipment rooms
Process and store criminal justice information only within a physically secure location or controlled area.
- Site assessment
- Badge access logs
- Camera coverage map
- Remote workstations not assessed
- Shared tenant spaces uncontrolled
- Camera coverage gaps
Physical and Environmental Security
Implement physical security controls for facilities processing CJI
- Physically secure location list
- Access control logs
- Visitor procedure
- Environmental controls
- Access logs incomplete
- Visitor unmanaged
- Controls weak
Establish policies and controls for mobile devices accessing CJI
- Mobile device policy
- MDM enrolment records
- Compliance reports
- Lost device procedure
- MDM gaps
- Lost device weak
- Compliance reports absent
Requirements for cloud services processing or storing CJI
- Cloud service authorisation
- FedRAMP package
- Customer responsibility matrix
- Continuous monitoring evidence
- Matrix absent
- Monitoring weak
- Authorisation stale
Risk and Supply Chain
Conduct risk assessments of systems processing CJI
- Risk assessment methodology
- System risk register
- Treatment plan
- Annual review
- Methodology weak
- Register stale
- Review absent
Assess and authorize systems for processing CJI
- Security plan
- Assessment report
- Authorisation decision
- POA&M tracker
- POA&M stale
- Authorisation lapsed
- Plan outdated
Manage supply chain risks for systems and services processing CJI
- SCRM policy
- Supplier inventory
- Component provenance records
- Continuous monitoring
- Provenance unknown
- Monitoring absent
- Inventory incomplete
Incorporate security requirements in system and service acquisitions
- Acquisition policy
- Security requirements schedule
- Vendor evaluation records
- Contract clauses
- Requirements weak
- Evaluation shallow
- Clauses absent
System Security
Maintain integrity of systems and information including malware protection
- Flaw remediation procedure
- Malware protection inventory
- Monitoring evidence
- Incident response records
- Remediation lag
- Monitoring gaps
- IR weak
Maintain secure configurations for systems processing CJI
- CM policy
- Baseline configuration inventory
- Change control records
- Authorised software list
- Baselines absent
- Change control weak
- Software list stale
Protect media containing CJI including encryption and secure disposal
- Media handling procedure
- Sanitisation records
- Transport log
- Destruction certificates
- Sanitisation weak
- Transport untracked
- Destruction undocumented
Protect systems and communications including encryption of CJI in transit
- Cryptographic policy
- FIPS 140 validated module inventory
- Key management procedure
- Network protection design
- FIPS modules expired
- Key management weak
- Design outdated
System and Communications Protection
Protect criminal justice information in transit and at rest using FIPS-validated cryptography and segment networks appropriately.
- FIPS 140-3 certificate references
- Network diagram
- Key management procedure
- Non-validated modules in use
- Flat network between CJI and non-CJI
- Key rotation not tracked
Monitor and control communications at the external boundary and at key internal boundaries of systems processing criminal justice information.
- Firewall ruleset review
- IDS alert sample
- Network monitoring dashboard
- Any-any rules
- No internal segmentation between CJI and corporate
- No alert tuning
Secure wireless access to criminal justice information using approved encryption, authentication, and rogue access point detection.
- Wireless controller configuration
- Rogue AP scan report
- Authentication logs
- WPA2-Personal still used
- Guest network shares infrastructure
- No rogue AP detection
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FBI CJIS Security Policy framework page.