FBI CJIS Security Policy
What is FBI CJIS Security Policy?
The FBI Criminal Justice Information Services (CJIS) Security Policy establishes minimum security requirements for access to FBI CJIS Division systems and information including the National Crime Information Center (NCIC), Interstate Identification Index (III), and National Instant Criminal Background Check System (NICS). Version 5.9.4 (2024) applies to all entities accessing criminal justice information (CJI) including law enforcement, contractors, and cloud service providers.. It comprises 33 controls organised across 19 domains, and applies in the United States (FBI).
How FBI CJIS Security Policy maps to other frameworks
All 33 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 19 domains FBI CJIS Security Policy groups its controls into
Where FBI CJIS Security Policy overlaps with the standards you already hold
What FBI CJIS Security Policy means in your sector
What FBI CJIS Security Policy means for your job
Questions people ask about FBI CJIS Security Policy
What is FBI CJIS Security Policy?
How many controls does FBI CJIS Security Policy have?
Where does FBI CJIS Security Policy apply?
What frameworks does FBI CJIS Security Policy map to?
How do I get started with FBI CJIS Security Policy compliance?
Query FBI CJIS Security Policy programmatically
FBI CJIS Security Policy, its 33 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
FBI CJIS Security Policy API reference and MCP config →What FBI CJIS Security Policy requires, control by control
Each page carries the requirement text for one FBI CJIS Security Policy control and what an assessor expects to see as evidence.
- CJIS-10 System and Information Integrity
- CJIS-14 Physical Protection
- CJIS-15 Mobile Devices
- CJIS-19 Supply Chain Risk Management
- CJIS-2 Security Awareness Training
- CJIS-3 Personnel Security
- CJIS-5-13 Mobile Devices
- CJIS-5-5 Access Control
- CJIS-5-6 Identification and Authentication
- CJIS-5-7 Configuration Management
How ready are you for FBI CJIS Security Policy?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.