Criminal justice information (CJI) must be protected from the ever-increasing security risks of the digital age. Therefore, organizations that handle CJI must comply with security standards established by the CJIS. In this article, we cover what is CJIS compliance, who must comply with it, what its requirements are, how to do so, and how you can tackle CJIS compliance in case it applies to your organization.

## **What is CJI?**

Criminal Justice Information (CJI) includes a vast array of data collected, managed, and stored by law enforcement agencies. CJI can include data such as criminal histories, arrest records, investigative reports, biometric data, etc. All of this information must remain confidential and be kept secure from unauthorized access.

In our digital age, CJI faces multiple cybersecurity threats: hacking, data breaches (both accidental or intentional), ransomware attacks, non-secure Wi-Fi networks, loss of devices like laptops, etc.

To ensure the protection of CJI, the Criminal Justice Information Services (CJIS) was established. This article will guide you through what CJIS compliance is, who is required to comply with it, what the CJIS security requirements are, and how to comply with it. Let’s begin.

## **What does CJIS stand for?**

CJIS stands for [Criminal Justice Information Services](https://www.fbi.gov/services/cjis) and is the largest division of the FBI. It was created in 1992 and includes several departments such as the National Crime Information Center (NCIC) and the Integrated Automated Fingerprint Identification System (IAFIS) to mention a few. The CJIS works with law enforcement, national security, and intelligence agencies across the United States. The services it provides include access to databases, biometric services, analysis and reporting on crime, background checks, and more.

## **What are the CJIS requirements?**

The CJIS established a set of security standards called the [CJIS Security Policy](https://www.fbi.gov/file-repository/cjis_security_policy_v5-9_20200601.pdf/view) and outlines how organizations must ensure the security of criminal justice information. Individuals and organizations that handle CJI must comply with it to ensure that sensitive information remains secure. Failure to meet these security standards (which we’ll dive into in a bit) can result in access to CJI being revoked, having to pay fines, and even facing criminal charges.

The security requirements are divided into 13 policy areas:

01. **Information exchange agreements:** An agreement between parties that share CJI with each other which specifies their roles, responsibilities, and security safeguards.  
02. **Basic security awareness training:** Personnel with access to CJI to undergo basic security awareness training.  
03. **Incident response:** A plan that details procedures for identifying, reporting, mitigating, and recovering from security incidents.  
04. **Auditing and accountability:** Organizations must monitor and log who accesses CJI, when, and why. By auditing these logs, they evaluate compliance and ensure accountability.  
05. **Access control:** There must be rules for granting, monitoring, and restricting access to CJI based on user roles and the principle of least privilege.  
06. **Identification and authentication:** Any person who is granted access to CJI must verify their identity using strong identification and authentication methods.  
07. **Configuration management:** Only qualified and authorized personnel can access the CJI information system to perform upgrades or modifications.  
08. **Media protection:** Access to physical and digital media must be restricted to authorized individuals and follow procedures that are documented and implemented.  
09. **Physical protection:** Organizations must have physically secure locations where CJI is stored. They must control and monitor access to those locations.  
10. **Systems and communications protection and information integrity:** Application, services, and information systems must ensure the system’s integrity by detecting and protecting against unauthorized changes to information and software.  
11. **Formal audits:** Organizations will undergo formal audits to ensure compliance with CJIS security standards.  
12. **Personnel security:** To protect CJI from insider threats, this policy specifies requirements for personnel termination, transfer, and sanctions for failing to comply with established security policies and procedures.  
13. **Mobile devices:** There must be measures in place to restrict usage of mobile devices as well as the accessing, monitoring, and control of wireless communications.

Admittedly, meeting the security requirements for all of these 13 areas to obtain CJIS certification can be an arduous undertaking.

As you establish policies and procedures to comply with CJIS, you will notice that a lot of the criminal justice information your organization handles includes personal data. What kind of data exactly? Let’s find out.

### **What types of data is included in CJI?**

Criminal justice information includes multiple types of personal information, namely:

- **Biometric Data:** physical or biological data such as facial recognition data, fingerprints, etc.  
- **Identity History Data:** Records of an individual's criminal history e.g. arrest records, convictions, etc.  
- **Biographical Data:** Descriptive information about an individual that helps identify them and complements biometric data and identity history data during criminal justice processes.  
- **Personally Identifiable Information (PII):** Any data that can identify an individual, such as name, address, credit card number, passport number, etc.

The handling of this personal data is tightly regulated under the CJIS Security Policy, which mandates strict controls over the lifecycle of CJI, from creation and storage to transmission and destruction. In fact, sometimes you will have to deal with hundreds of documents that contain personal data, and that necessitates redacting it to keep it secure.

## **CJIS compliance checklist**

Use this comprehensive checklist to assess your organization's current CJIS compliance status and identify areas that need attention. Each item corresponds to the 13 CJIS Security Policy areas and includes practical verification steps.

**Information Exchange Agreements**

- Executed formal agreements with all parties that share CJI  
- Agreements specify roles, responsibilities, and security safeguards  
- Regular review schedule established for agreement updates  
- Contact information for all parties kept current

**Security Awareness Training**

- All personnel with CJI access completed initial security training  
- Annual refresher training program implemented  
- Training records maintained and up-to-date  
- Training covers redaction best practices and data handling procedures  
- Knowledge assessments completed and documented

**Incident Response**

- Written Incident Response Plan (IRP) developed and approved  
- IRP includes procedures for identification, reporting, containment, and recovery  
- Response team roles and contact information clearly defined  
- Regular testing and simulation exercises conducted  
- Incident reporting procedures established with appropriate authorities

**Auditing and Accountability**

- Comprehensive audit logging system implemented  
- User access activities monitored and recorded  
- Log reviews conducted regularly  
- Audit trail integrity protection measures in place  
- Retention schedules for audit logs established

**Access Control**

- Role-based access control system implemented  
- Principle of least privilege enforced  
- User access reviews conducted periodically  
- Access termination procedures established  
- Guest and temporary access protocols defined

**Identification and Authentication**

- Strong authentication methods implemented for all users  
- Multi-factor authentication enabled where required  
- Password policies meet CJIS standards  
- Account lockout procedures established  
- Regular authentication system reviews conducted

**Configuration Management**

- System baseline configurations documented  
- Change control procedures implemented  
- Only authorized personnel can modify systems  
- Configuration changes tracked and approved  
- Regular system integrity checks performed

**Media Protection**

- Physical media access controls implemented  
- Digital media encryption standards met  
- Secure media disposal procedures established  
- Media transportation security protocols defined  
- Media inventory and tracking system maintained

**Physical Protection**

- Secure facilities for CJI storage and access established  
- Physical access controls and monitoring systems installed  
- Visitor access procedures documented and followed  
- Environmental controls (fire, flood, temperature) implemented  
- Regular physical security assessments conducted

**System and Communications Protection**

- Data encryption implemented for data in transit and at rest  
- Network security controls and monitoring established  
- System integrity verification procedures implemented  
- Secure communication protocols used  
- Regular vulnerability assessments conducted

**Information Integrity**

- Data integrity verification measures implemented  
- Unauthorized change detection systems in place  
- Regular data backup and recovery testing performed  
- Document redaction procedures ensure permanent removal of sensitive data  
- Version control systems for sensitive documents maintained

**Formal Audits**

- Annual compliance audits scheduled and completed  
- Audit findings documented and remediation plans developed  
- Compliance gaps identified and addressed promptly  
- Audit documentation maintained for required retention periods  
- Continuous monitoring program established

**Personnel Security**

- Background check procedures implemented for all CJI-accessing personnel  
- Personnel security policies documented and communicated  
- Termination procedures include access revocation protocols  
- Personnel sanctions policy established for security violations  
- Regular personnel security reviews conducted

**Mobile Devices**

- Mobile device usage policies established and enforced  
- Device encryption and security controls implemented  
- Remote wipe capabilities enabled for organizational devices  
- Wireless communication security protocols established  
- Regular mobile device security assessments conducted

## **10 steps to comply with the CJIS requirements**

To comply with the security requirements of the CJIS, we recommend that your organization takes the following 10 steps:

### 1. Review and understand the CJIS Security Policy

First, you need to make sure all personnel with access to CJI fully understands the CJIS Security Policy.

### 2. Assign a CJIS Security Officer (CSO)

To centralize communication and accountability, you want to have a CJIS Security Officer who acts as a point of contact with the CJIS.

### 3. Implement technical safeguards

Unauthorized access to CJI must be prevented at all times.

### 4. Ensure the security of physical locations where CJI is stored and/or accessed

In addition to cyber threats, physical access to CJI is a concern that needs to be addressed.

### 5. Conduct background checks on personnel with access to CJI

Only vetted and trustworthy individuals should be allowed to handle CJI.

### 6. Provide adequate training to personnel

Your personnel needs adequate training on how to handle CJI.

### 7. Create internal policies that adhere to the CJIS Security Policy

Your organization needs to have internal policies for CJIS compliance.

### 8. Ensure that third-party vendors and contractors comply with the CJIS

Any third-party entities you work with should comply with the CJIS Security Policy as well.

### 9. Establish an Incident Response Plan

Like we mentioned earlier while discussing the security requirements, you need to have an IRP in place and follow it if an incident occurs.

### 10. Stay up-to-date with the latest changes in the CJIS Security Policy

Lastly, you want to keep up with the latest CJIS standards to protect all CJI from new threats.

### **Roles and responsibilities in CJIS compliance**

Successful CJIS compliance requires clearly defined roles and responsibilities across your organization. Here are the key positions and their essential duties in maintaining CJIS compliance.

#### **Local Agency Security Officer (LASO)**
**Key responsibilities include:**  
- **Policy compliance oversight**  
- **Information security liaison**  
- **Training coordination**  
- **Incident management**  
- **Access control administration**  
- **Documentation maintenance**  
- **Hardware and software oversight**  
- **Audit assistance**

#### **CJIS Security Officer (CSO) / Chief Security Officer**
**Primary responsibilities include:**  
- **Strategic security leadership**  
- **Policy development and enforcement**  
- **Risk management**  
- **Compliance oversight**  
- **Incident response coordination**  
- **Staff management**  
- **Vendor management**  
- **Communication liaison**  
- **Audit preparation**  
- **Resource allocation**

#### **Information Security Officer (ISO) / CSA ISO**
**Core responsibilities encompass:**  
- **Technical compliance management**  
- **Security policy development**  
- **Threat and vulnerability assessment**  
- **Risk and control assessments**  
- **Security operations governance**  
- **Training program development**  
- **FBI liaison coordination**  
- **Security architecture**  
- **Compliance monitoring**  
- **Documentation management**

#### **Terminal Agency Coordinator (TAC)**
**Key duties include:**  
- **System administration**  
- **User account management**  
- **Training coordination**  
- **Quality assurance**  
- **Communication facilitation**  
- **Documentation maintenance**  
- **Compliance monitoring**

#### **Agreement Coordinator (AC)**
**Primary functions include:**  
- **Contract oversight**  
- **Compliance verification**  
- **Agreement negotiation**  
- **Vendor communication**  
- **Documentation management**

## **CJIS compliance vs. other data security frameworks**

Understanding how CJIS compliance compares to other major data protection regulations helps organizations navigate overlapping requirements and develop comprehensive security strategies.

| Framework        | CJIS                          | HIPAA                     | GDPR                    |
|------------------|-------------------------------|---------------------------|-------------------------|
| Full Name        | Criminal Justice Information Services Security Policy | Health Insurance Portability and Accountability Act | General Data Protection Regulation |
| Year Established | 2025 (Current version 6.0) | 1996                      | 2018                    |
| Geographic Scope  | United States                | United States            | European Union (Global impact) |
| Industry Focus    | Law enforcement and criminal justice | Healthcare and health insurance | All industries processing EU data |
| Data Protected    | Criminal Justice Information (CJI), fingerprints, arrest records, investigative reports | Protected Health Information (PHI) and electronic PHI (ePHI) | Personal data of EU residents |
| Enforcement Authority | FBI CJIS Division          | Department of Health and Human Services (HHS) | Data Protection Authorities in each EU member state |
| Certification Available | No formal certification   | No formal certification   | No formal certification   |
| Maximum Penalties | Loss of access to FBI databases, criminal charges, fines | Up to $2 million per incident | Up to 4% of annual global revenue or €20 million |

### **Why is complying with the CJIS security requirements important?**

If criminal justice information is not protected from cybersecurity threats, the consequences can be rather dire for the entire nation. Non-compliance can lead to revoked access to CJI, fines, or criminal charges. Proper handling protects national security, law enforcement operations, and individuals’ privacy. Adhering to CJIS standards ensures the integrity and trustworthiness of criminal justice processes.

### **What role does redaction play in CJIS compliance?**

Redaction plays an essential role in protecting Personally Identifiable Information. When handling documents that contain CJI, you need to remove sensitive data like personal identifiers, victim details, or investigative information. By adhering to the principle of least privilege, redaction helps restrict access to only the information necessary for an individual’s role or task. Redaction aligns with CJIS requirements for access control and protects organizations from risks associated with data breaches.

## Protect sensitive data in CJIS with permanent redaction

When working with criminal justice information, you will often have to handle large volumes of documents with countless data points, many of which contain sensitive information. So to achieve CJIS compliance, you need precision and efficiency.
