Skip to content

Evidence request lists

FBI CJIS Security Policy

Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Control

CJIS-5.5
Access Control

Enforce role-based access, least privilege, separation of duties, and session controls for access to criminal justice information.

Artefacts an auditor will ask for
  • Role catalog
  • Access review report
  • Session timeout configuration
Where this commonly fails
  • Standing administrator accounts
  • No separation of duties for evidence review
  • Session timeouts too long

Account Management

CJIS-AM-1
Account Management

Create, modify, disable, and remove accounts based on documented authorization and review accounts at defined intervals.

Artefacts an auditor will ask for
  • Joiner-mover-leaver workflow
  • Quarterly access review evidence
  • Disabled account list
Where this commonly fails
  • Dormant accounts not disabled
  • Movers retain prior access
  • Reviews not signed off by data owner

Audit

CJIS-5.4
Auditing and Accountability

Generate, protect, and retain audit records sufficient to reconstruct events and support investigations.

Artefacts an auditor will ask for
  • Logged event catalog
  • SIEM retention configuration
  • Audit review evidence
Where this commonly fails
  • Privileged actions not logged
  • Retention shorter than one year
  • No documented review cadence

Awareness and Training

CJIS-5.2
Security Awareness Training

Provide CJIS security awareness training to all personnel with access to criminal justice information at hire and at least every two years.

Artefacts an auditor will ask for
  • CJIS training plan
  • Learner transcripts
  • Quiz results
Where this commonly fails
  • Contractors not enrolled
  • No level-appropriate content for elevated roles
  • Refresh cycle exceeded

Compliance

CJIS-5.11
Formal Audits

Subject systems and processes to formal CJIS audits at least every three years and remediate findings.

Artefacts an auditor will ask for
  • Triennial audit report
  • CAP tracker
  • Closure evidence
Where this commonly fails
  • Findings open beyond agreed timelines
  • No evidence library
  • Reauditing scope reduced without justification

Configuration Management

CJIS-5.7
Configuration Management

Establish and maintain baseline configurations for systems handling criminal justice information and control changes through a documented process.

Artefacts an auditor will ask for
  • CIS or DISA STIG baseline
  • Change tickets
  • Asset inventory
Where this commonly fails
  • Baselines not benchmarked
  • Emergency changes bypass review
  • Inventory missing mobile devices
CJIS-CM-1
Cloud Service Provider Controls

Where cloud services process criminal justice information, ensure CJIS-specific controls are inherited or implemented and evidenced by the provider.

Artefacts an auditor will ask for
  • Provider CJIS attestation
  • Shared responsibility matrix
  • Customer-managed control evidence
Where this commonly fails
  • No CJIS-specific attestation
  • Customer responsibilities not assigned
  • FedRAMP scope mismatch

Governance and Agreements

CJIS-1
Information Exchange Agreements

Establish information exchange agreements outlining roles, responsibilities and data ownership for CJI

Artefacts an auditor will ask for
  • Information exchange agreement
  • Connected agency register
  • Authorisation records
  • Annual review
Where this commonly fails
  • Agreements stale
  • Register incomplete
  • Review skipped
CJIS-2
Security Awareness Training

Conduct regular personnel training on CJI risks, handling and incident reporting

Artefacts an auditor will ask for
  • Awareness training curriculum
  • Completion records
  • Role-based modules
  • Annual refresh evidence
Where this commonly fails
  • Role-based modules absent
  • Refresh skipped
  • Completion gaps
CJIS-3
Personnel Security

Screen and vet personnel with access to CJI through background checks

Artefacts an auditor will ask for
  • Background check policy
  • Fingerprint records
  • Adjudication log
  • Reinvestigation schedule
Where this commonly fails
  • Reinvestigation skipped
  • Adjudication weak
  • Records incomplete

Identification and Authentication

CJIS-5.6
Identification and Authentication

Uniquely identify users and use advanced authentication for access to criminal justice information from non-secure locations.

Artefacts an auditor will ask for
  • MFA enforcement report
  • Identity proofing records
  • Password policy
Where this commonly fails
  • SMS used as second factor
  • Shared accounts for kiosk use
  • No re-proofing after role change

Incident Response

CJIS-5.3
Incident Response

Implement an incident response capability covering detection, analysis, containment, eradication, recovery, and reporting to the CJIS Systems Officer.

Artefacts an auditor will ask for
  • Incident response plan
  • Tabletop exercise report
  • CSO notification log
Where this commonly fails
  • No tabletop in last 12 months
  • Reporting timelines not met
  • Forensic preservation steps missing
CJIS-IR-2
Notification to CJIS Systems Officer

Notify the CJIS Systems Officer of incidents involving criminal justice information within required timeframes.

Artefacts an auditor will ask for
  • CSO notification record
  • Incident report template
  • Post-incident review
Where this commonly fails
  • Notifications informal and undated
  • Reporting template missing required fields
  • No CSA coordination evidence

Information Exchange

CJIS-5.1
Information Exchange Agreements

Establish written agreements that govern the exchange of criminal justice information between agencies and service providers.

Artefacts an auditor will ask for
  • Signed CJIS information exchange agreement
  • Management control agreement
  • Service provider security addendum
Where this commonly fails
  • Agreements not refreshed on contract changes
  • Missing CJIS Security Addendum for vendors
  • No central register of agreements

Media Protection

CJIS-5.8
Media Protection

Protect digital and physical media containing criminal justice information from unauthorized access and securely sanitize or destroy media at end of life.

Artefacts an auditor will ask for
  • Media handling SOP
  • Sanitization certificates
  • Chain of custody log
Where this commonly fails
  • No certificate of destruction
  • Reuse of media across classifications
  • Couriers not vetted

Mobile

CJIS-5.13
Mobile Devices

Apply additional controls for mobile devices accessing criminal justice information, including device management, encryption, and remote wipe.

Artefacts an auditor will ask for
  • MDM policy and enrolment report
  • Encryption attestation
  • Wipe procedure
Where this commonly fails
  • BYOD devices unmanaged
  • No remote wipe
  • Geofencing not applied to in-vehicle MDTs

Personnel

CJIS-5.12
Personnel Security

Conduct fingerprint-based background checks and approval prior to granting unescorted access to criminal justice information.

Artefacts an auditor will ask for
  • Fingerprint submission records
  • Adjudication memo
  • Termination access removal log
Where this commonly fails
  • Background checks not refreshed for high-risk roles
  • Contractor checks performed by vendor only
  • Access removed late on separation

Physical Security

CJIS-5.9
Physical Protection

Restrict physical access to systems and facilities that process criminal justice information to authorized personnel and protect against environmental hazards.

Artefacts an auditor will ask for
  • Access list
  • Visitor logs
  • Environmental monitoring reports
Where this commonly fails
  • Tailgating not addressed
  • Visitor logs paper-only and incomplete
  • No fire suppression in equipment rooms
CJIS-PE-2
Physically Secure Location

Process and store criminal justice information only within a physically secure location or controlled area.

Artefacts an auditor will ask for
  • Site assessment
  • Badge access logs
  • Camera coverage map
Where this commonly fails
  • Remote workstations not assessed
  • Shared tenant spaces uncontrolled
  • Camera coverage gaps

Physical and Environmental Security

CJIS-14
Physical Protection

Implement physical security controls for facilities processing CJI

Artefacts an auditor will ask for
  • Physically secure location list
  • Access control logs
  • Visitor procedure
  • Environmental controls
Where this commonly fails
  • Access logs incomplete
  • Visitor unmanaged
  • Controls weak
CJIS-15
Mobile Devices

Establish policies and controls for mobile devices accessing CJI

Artefacts an auditor will ask for
  • Mobile device policy
  • MDM enrolment records
  • Compliance reports
  • Lost device procedure
Where this commonly fails
  • MDM gaps
  • Lost device weak
  • Compliance reports absent
CJIS-16
Cloud Computing

Requirements for cloud services processing or storing CJI

Artefacts an auditor will ask for
  • Cloud service authorisation
  • FedRAMP package
  • Customer responsibility matrix
  • Continuous monitoring evidence
Where this commonly fails
  • Matrix absent
  • Monitoring weak
  • Authorisation stale

Risk and Supply Chain

CJIS-17
Risk Assessment

Conduct risk assessments of systems processing CJI

Artefacts an auditor will ask for
  • Risk assessment methodology
  • System risk register
  • Treatment plan
  • Annual review
Where this commonly fails
  • Methodology weak
  • Register stale
  • Review absent
CJIS-18
Security Assessment and Authorization

Assess and authorize systems for processing CJI

Artefacts an auditor will ask for
  • Security plan
  • Assessment report
  • Authorisation decision
  • POA&M tracker
Where this commonly fails
  • POA&M stale
  • Authorisation lapsed
  • Plan outdated
CJIS-19
Supply Chain Risk Management

Manage supply chain risks for systems and services processing CJI

Artefacts an auditor will ask for
  • SCRM policy
  • Supplier inventory
  • Component provenance records
  • Continuous monitoring
Where this commonly fails
  • Provenance unknown
  • Monitoring absent
  • Inventory incomplete
CJIS-20
System Acquisition

Incorporate security requirements in system and service acquisitions

Artefacts an auditor will ask for
  • Acquisition policy
  • Security requirements schedule
  • Vendor evaluation records
  • Contract clauses
Where this commonly fails
  • Requirements weak
  • Evaluation shallow
  • Clauses absent

System Security

CJIS-10
System and Information Integrity

Maintain integrity of systems and information including malware protection

Artefacts an auditor will ask for
  • Flaw remediation procedure
  • Malware protection inventory
  • Monitoring evidence
  • Incident response records
Where this commonly fails
  • Remediation lag
  • Monitoring gaps
  • IR weak
CJIS-7
Configuration Management

Maintain secure configurations for systems processing CJI

Artefacts an auditor will ask for
  • CM policy
  • Baseline configuration inventory
  • Change control records
  • Authorised software list
Where this commonly fails
  • Baselines absent
  • Change control weak
  • Software list stale
CJIS-8
Media Protection

Protect media containing CJI including encryption and secure disposal

Artefacts an auditor will ask for
  • Media handling procedure
  • Sanitisation records
  • Transport log
  • Destruction certificates
Where this commonly fails
  • Sanitisation weak
  • Transport untracked
  • Destruction undocumented
CJIS-9
System and Communications Protection

Protect systems and communications including encryption of CJI in transit

Artefacts an auditor will ask for
  • Cryptographic policy
  • FIPS 140 validated module inventory
  • Key management procedure
  • Network protection design
Where this commonly fails
  • FIPS modules expired
  • Key management weak
  • Design outdated

System and Communications Protection

CJIS-5.10
System and Communications Protection

Protect criminal justice information in transit and at rest using FIPS-validated cryptography and segment networks appropriately.

Artefacts an auditor will ask for
  • FIPS 140-3 certificate references
  • Network diagram
  • Key management procedure
Where this commonly fails
  • Non-validated modules in use
  • Flat network between CJI and non-CJI
  • Key rotation not tracked
CJIS-SC-1
Boundary Protection

Monitor and control communications at the external boundary and at key internal boundaries of systems processing criminal justice information.

Artefacts an auditor will ask for
  • Firewall ruleset review
  • IDS alert sample
  • Network monitoring dashboard
Where this commonly fails
  • Any-any rules
  • No internal segmentation between CJI and corporate
  • No alert tuning
CJIS-SC-2
Wireless Network Protections

Secure wireless access to criminal justice information using approved encryption, authentication, and rogue access point detection.

Artefacts an auditor will ask for
  • Wireless controller configuration
  • Rogue AP scan report
  • Authentication logs
Where this commonly fails
  • WPA2-Personal still used
  • Guest network shares infrastructure
  • No rogue AP detection
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FBI CJIS Security Policy framework page.