CJIS Compliance Guide: Meaning, Requirements & Checklist

Criminal justice information (CJI) must be protected from the ever-increasing security risks of the digital age. Therefore, organizations that handle CJI must comply with security standards established by the CJIS. In this article, we cover what is CJIS compliance, who must comply with it, what its requirements are, how to do so, and how you can tackle CJIS compliance in case it applies to your organization.

What is CJI?

Criminal Justice Information (CJI) includes a vast array of data collected, managed, and stored by law enforcement agencies. CJI can include data such as criminal histories, arrest records, investigative reports, biometric data, etc. All of this information must remain confidential and be kept secure from unauthorized access.

In our digital age, CJI faces multiple cybersecurity threats: hacking, data breaches (both accidental or intentional), ransomware attacks, non-secure Wi-Fi networks, loss of devices like laptops, etc.

To ensure the protection of CJI, the Criminal Justice Information Services (CJIS) was established. This article will guide you through what CJIS compliance is, who is required to comply with it, what the CJIS security requirements are, and how to comply with it. Let’s begin.

What does CJIS stand for?

CJIS stands for Criminal Justice Information Services and is the largest division of the FBI. It was created in 1992 and includes several departments such as the National Crime Information Center (NCIC) and the Integrated Automated Fingerprint Identification System (IAFIS) to mention a few. The CJIS works with law enforcement, national security, and intelligence agencies across the United States. The services it provides include access to databases, biometric services, analysis and reporting on crime, background checks, and more.

What are the CJIS requirements?

The CJIS established a set of security standards called the CJIS Security Policy and outlines how organizations must ensure the security of criminal justice information. Individuals and organizations that handle CJI must comply with it to ensure that sensitive information remains secure. Failure to meet these security standards (which we’ll dive into in a bit) can result in access to CJI being revoked, having to pay fines, and even facing criminal charges.

The security requirements are divided into 13 policy areas:

  1. Information exchange agreements: An agreement between parties that share CJI with each other which specifies their roles, responsibilities, and security safeguards.
  2. Basic security awareness training: Personnel with access to CJI to undergo basic security awareness training.
  3. Incident response: A plan that details procedures for identifying, reporting, mitigating, and recovering from security incidents.
  4. Auditing and accountability: Organizations must monitor and log who accesses CJI, when, and why. By auditing these logs, they evaluate compliance and ensure accountability.
  5. Access control: There must be rules for granting, monitoring, and restricting access to CJI based on user roles and the principle of least privilege.
  6. Identification and authentication: Any person who is granted access to CJI must verify their identity using strong identification and authentication methods.
  7. Configuration management: Only qualified and authorized personnel can access the CJI information system to perform upgrades or modifications.
  8. Media protection: Access to physical and digital media must be restricted to authorized individuals and follow procedures that are documented and implemented.
  9. Physical protection: Organizations must have physically secure locations where CJI is stored. They must control and monitor access to those locations.
  10. Systems and communications protection and information integrity: Application, services, and information systems must ensure the system’s integrity by detecting and protecting against unauthorized changes to information and software.
  11. Formal audits: Organizations will undergo formal audits to ensure compliance with CJIS security standards.
  12. Personnel security: To protect CJI from insider threats, this policy specifies requirements for personnel termination, transfer, and sanctions for failing to comply with established security policies and procedures.
  13. Mobile devices: There must be measures in place to restrict usage of mobile devices as well as the accessing, monitoring, and control of wireless communications.

Admittedly, meeting the security requirements for all of these 13 areas to obtain CJIS certification can be an arduous undertaking.

As you establish policies and procedures to comply with CJIS, you will notice that a lot of the criminal justice information your organization handles includes personal data. What kind of data exactly? Let’s find out.

What types of data is included in CJI?

Criminal justice information includes multiple types of personal information, namely:

The handling of this personal data is tightly regulated under the CJIS Security Policy, which mandates strict controls over the lifecycle of CJI, from creation and storage to transmission and destruction. In fact, sometimes you will have to deal with hundreds of documents that contain personal data, and that necessitates redacting it to keep it secure.

CJIS compliance checklist

Use this comprehensive checklist to assess your organization's current CJIS compliance status and identify areas that need attention. Each item corresponds to the 13 CJIS Security Policy areas and includes practical verification steps.

Information Exchange Agreements

Security Awareness Training

Incident Response

Auditing and Accountability

Access Control

Identification and Authentication

Configuration Management

Media Protection

Physical Protection

System and Communications Protection

Information Integrity

Formal Audits

Personnel Security

Mobile Devices

10 steps to comply with the CJIS requirements

To comply with the security requirements of the CJIS, we recommend that your organization takes the following 10 steps:

1. Review and understand the CJIS Security Policy

First, you need to make sure all personnel with access to CJI fully understands the CJIS Security Policy.

2. Assign a CJIS Security Officer (CSO)

To centralize communication and accountability, you want to have a CJIS Security Officer who acts as a point of contact with the CJIS.

3. Implement technical safeguards

Unauthorized access to CJI must be prevented at all times.

4. Ensure the security of physical locations where CJI is stored and/or accessed

In addition to cyber threats, physical access to CJI is a concern that needs to be addressed.

5. Conduct background checks on personnel with access to CJI

Only vetted and trustworthy individuals should be allowed to handle CJI.

6. Provide adequate training to personnel

Your personnel needs adequate training on how to handle CJI.

7. Create internal policies that adhere to the CJIS Security Policy

Your organization needs to have internal policies for CJIS compliance.

8. Ensure that third-party vendors and contractors comply with the CJIS

Any third-party entities you work with should comply with the CJIS Security Policy as well.

9. Establish an Incident Response Plan

Like we mentioned earlier while discussing the security requirements, you need to have an IRP in place and follow it if an incident occurs.

10. Stay up-to-date with the latest changes in the CJIS Security Policy

Lastly, you want to keep up with the latest CJIS standards to protect all CJI from new threats.

Roles and responsibilities in CJIS compliance

Successful CJIS compliance requires clearly defined roles and responsibilities across your organization. Here are the key positions and their essential duties in maintaining CJIS compliance.

Local Agency Security Officer (LASO)

Key responsibilities include:

CJIS Security Officer (CSO) / Chief Security Officer

Primary responsibilities include:

Information Security Officer (ISO) / CSA ISO

Core responsibilities encompass:

Terminal Agency Coordinator (TAC)

Key duties include:

Agreement Coordinator (AC)

Primary functions include:

CJIS compliance vs. other data security frameworks

Understanding how CJIS compliance compares to other major data protection regulations helps organizations navigate overlapping requirements and develop comprehensive security strategies.

Framework CJIS HIPAA GDPR
Full Name Criminal Justice Information Services Security Policy Health Insurance Portability and Accountability Act General Data Protection Regulation
Year Established 2025 (Current version 6.0) 1996 2018
Geographic Scope United States United States European Union (Global impact)
Industry Focus Law enforcement and criminal justice Healthcare and health insurance All industries processing EU data
Data Protected Criminal Justice Information (CJI), fingerprints, arrest records, investigative reports Protected Health Information (PHI) and electronic PHI (ePHI) Personal data of EU residents
Enforcement Authority FBI CJIS Division Department of Health and Human Services (HHS) Data Protection Authorities in each EU member state
Certification Available No formal certification No formal certification No formal certification
Maximum Penalties Loss of access to FBI databases, criminal charges, fines Up to $2 million per incident Up to 4% of annual global revenue or €20 million

Why is complying with the CJIS security requirements important?

If criminal justice information is not protected from cybersecurity threats, the consequences can be rather dire for the entire nation. Non-compliance can lead to revoked access to CJI, fines, or criminal charges. Proper handling protects national security, law enforcement operations, and individuals’ privacy. Adhering to CJIS standards ensures the integrity and trustworthiness of criminal justice processes.

What role does redaction play in CJIS compliance?

Redaction plays an essential role in protecting Personally Identifiable Information. When handling documents that contain CJI, you need to remove sensitive data like personal identifiers, victim details, or investigative information. By adhering to the principle of least privilege, redaction helps restrict access to only the information necessary for an individual’s role or task. Redaction aligns with CJIS requirements for access control and protects organizations from risks associated with data breaches.

Protect sensitive data in CJIS with permanent redaction

When working with criminal justice information, you will often have to handle large volumes of documents with countless data points, many of which contain sensitive information. So to achieve CJIS compliance, you need precision and efficiency.