10.4 COLLECT, Information Sharing & Computer Crime Familiarization
Key Takeaways
- COLLECT is DESPP's statewide system giving more than 180 authorized agencies access to NCIC, NLETS, DMV, Sex Offender Registry, Protective Order Registry (CGS § 51-5c), Department of Correction, and criminal history data from a single terminal, with access guaranteed to municipal departments free of charge under CGS § 7-281a.
- Every COLLECT query must be for a legitimate law enforcement purpose, independently verified before enforcement action when practical, and never disclosed to unauthorized third parties — CGS § 51-5c explicitly bars public access to the system.
- The Connecticut Information Sharing System (CISS) solves a different problem than COLLECT: it enables interagency case and incident information sharing across Connecticut's many separate municipal departments, rather than centralizing lookups against national master databases.
- Connecticut's computer crime statutes (CGS §§ 53a-250 through 53a-261) define unauthorized access, theft of computer services, and related offenses, with severity graded by dollar value of damage/services and risk of physical injury — computer crime in the third degree (CGS § 53a-254) is a Class D felony above $1,000 in damage or value.
- Patrol-level digital evidence preservation means securing a device without operating or unlocking it, isolating it from network connectivity only with proper approved equipment, documenting its condition as found, and obtaining consent or a warrant before any examination — actual forensic analysis belongs to specialized personnel.
10.4 COLLECT, Information Sharing & Computer Crime Familiarization
Core Principle: This section clusters three related POSTC curriculum areas — COLLECT (614), the Connecticut Information Sharing System (628), and Computer Crime Familiarization (602A) — around a single theme: modern patrol work runs on shared law enforcement data systems, and every officer who queries one of these systems is personally accountable for using it lawfully, accurately, and only for a legitimate law enforcement purpose. This is not an advanced digital-forensics course; it is baseline familiarity every patrol officer needs before touching a terminal or preserving a phone as evidence.
COLLECT: Connecticut On-Line Law Enforcement Communications Teleprocessing (Area 614)
COLLECT is the Department of Emergency Services and Public Protection (DESPP) statewide system that gives more than 180 authorized Connecticut law enforcement and criminal justice agencies access to state and federal criminal justice data from a single terminal.
What COLLECT Connects To
| System | What It Provides |
|---|---|
| National Crime Information Center (NCIC) | National criminal justice data shared across the U.S. and Canada (wants/warrants, stolen property, missing persons) |
| National Law Enforcement Telecommunications System (NLETS) | Interstate messaging and access to other states' motor vehicle and criminal history information |
| Connecticut DMV | Vehicle registration and driver's license data |
| Sex Offender Registry (SOR) | Registered sex offender information |
| Protective Order Registry (POR) | Active protective/restraining order data — accessed through COLLECT under CGS § 51-5c, which specifically designates COLLECT as the access point for this registry |
| Department of Correction (DOC) | Custody status information |
| State Police Criminal History (CCH) and Weapons files | Criminal history and firearms-related records |
| Paperless Re-Arrest Warrant Network (PRAWN) | Electronic warrant processing |
Statutory Access Guarantee
CGS § 7-281a specifically guarantees every municipal police department access to and use of COLLECT without charge — recognizing that consistent, statewide access to this data is a baseline public-safety necessity, not an optional add-on service departments must budget for separately.
Core Rules of Use Every Recruit Must Internalize
- Authorized purpose only: Queries must be for a legitimate law enforcement or criminal justice purpose connected to the officer's duties — not personal curiosity, not favors for friends or family, and not checking on a current or former romantic partner. Misuse of criminal justice information systems is one of the most common sources of officer discipline and decertification referrals nationally, and Connecticut treats it the same way.
- Accuracy and verification: Data returned from COLLECT (a warrant hit, a protective order, a stolen-vehicle flag) must be independently verified before an officer takes enforcement action based on it whenever practical — hit confirmation procedures exist precisely because national databases can contain stale or erroneous entries.
- Need-to-know and confidentiality: CGS § 51-5c explicitly states that nothing in the statute permits public access to COLLECT — the system and the data it returns are for authorized personnel only, and officers may not disclose query results to unauthorized third parties.
- Audit trail awareness: Every COLLECT query is logged and attributable to the requesting officer and terminal; recruits should understand that "who accessed what, and why" is always reconstructable after the fact.
Connecticut Information Sharing System (Area 628)
The Connecticut Information Sharing System (CISS), coordinated through the state's Criminal Justice Information System (CJIS-CT) infrastructure, is built to solve a different problem than COLLECT: rather than centralizing lookups against national and state master databases, CISS focuses on interagency case and incident information sharing — helping local, state, and other criminal justice partners see connections across cases, agencies, and jurisdictions that a single department's records management system cannot show on its own (for example, recognizing that a subject in a new local incident has open cases or contacts in a neighboring jurisdiction).
- Purpose: Improve situational awareness and case coordination across Connecticut's many separate municipal police departments, which — unlike some states with fewer, larger agencies — means information sharing across jurisdictional lines is especially important for public safety.
- Access and training: Officers and analysts access CISS through role-based credentials and receive dedicated training (delivered through live instructor-led webinars coordinated by CJIS-CT) separate from COLLECT terminal training, reflecting that the two systems serve different operational purposes even though both fall under the broader CJIS-CT information-sharing mission.
- Same accountability principles apply: need-to-know access, accurate documentation of the officer's own agency's contributing data, and no sharing of results outside authorized channels.
Computer Crime Familiarization (Area 602A)
This curriculum area gives patrol officers baseline familiarity with Connecticut's computer crime statutes (CGS §§ 53a-250 through 53a-261) and basic digital-evidence-preservation habits — it is explicitly not a digital forensics certification, and recruits are not expected to conduct forensic examinations themselves.
Connecticut Computer Crime Statutes (Overview)
- CGS § 53a-250 (Definitions): Establishes the technical vocabulary (access, computer, computer network, computer services, computer system, data) used throughout the computer crime statutes.
- CGS § 53a-251 (Computer crime, defined): Establishes the underlying offense categories, including unauthorized access to a computer system, theft of computer services, interruption of computer services, and unauthorized disclosure/copying of data. A person has an affirmative defense to an unauthorized-access charge if they reasonably believed the owner had authorized (or would have authorized) the access.
- CGS §§ 53a-252 through 53a-256 (Degree classifications): Grade the offense based on factors such as the dollar value of the damage or services involved and whether the conduct created a risk of serious physical injury — for example, computer crime in the third degree (CGS § 53a-254) is a Class D felony when damage/value exceeds $1,000 or the conduct recklessly creates a risk of serious physical injury.
First-Responder Digital Evidence Preservation (Not Forensic Examination)
Patrol officers are the ones most likely to be first on scene with a device that will later matter to an investigation — a suspect's phone, a victim's laptop, a business's point-of-sale terminal. Baseline preservation habits taught at this level include:
- Do not operate the device beyond what is necessary to secure it — powering a phone on/off or unlocking it can alter timestamps, trigger remote wipe features, or overwrite data, and should be left to trained digital forensic examiners with proper authority (consent or warrant).
- Isolate from network connectivity when trained to do so safely — cutting a device off from cellular/Wi-Fi signal (e.g., placing it in a Faraday bag if the department has one available) can prevent a remote wipe command from reaching the device, but only using department-approved equipment and procedure.
- Document the device's state as found: screen contents visible without unlocking it, physical condition, and exact location/time of seizure — this becomes part of the chain-of-custody record covered in Chapter 7.
- Obtain proper legal authority before any examination: consent from an authorized party or a search warrant describing the device and the scope of the search — patrol officers do not have independent authority to search a seized device's contents just because they lawfully seized the device itself.
- Route to specialized personnel: Connecticut's state and larger municipal digital forensics units (and, for complex cases, state or federal partners) perform the actual examination; the patrol officer's job ends at proper seizure, documentation, and handoff.
Practical Synthesis
COLLECT, CISS, and computer crime familiarization all reduce to the same accountability principle that runs through this entire chapter: an officer's access to information — whether a national database, a shared case record, or a seized phone — must be exercised for a legitimate purpose, accurately, and within the officer's actual legal authority. Overreach in any of these three areas (an improper database query, sharing case information outside authorized channels, or examining a device without a warrant) creates the same kind of exposure covered in Section 4.4: civil liability, suppressed evidence, and potential decertification referrals.
An officer uses COLLECT to look up the current address of an ex-partner for purely personal reasons unrelated to any case. What rule of use does this violate?
What is the primary purpose of the Connecticut Information Sharing System (CISS), as distinguished from COLLECT?
A patrol officer lawfully seizes a suspect's smartphone as evidence. What is the academy-correct next step regarding the phone's contents?
You've completed this section
Continue exploring other exams