9.2 CJIS Security Policy: Access Control, MFA & Encryption

Key Takeaways

  • The FBI CJIS Security Policy (version 6.x: v6.0 released December 27, 2024 and v6.1 on June 25, 2026) sets minimum security requirements for any agency, including civilian-run PSAPs, that accesses, processes, stores, or transmits Criminal Justice Information (CJI).
  • Criminal Justice Information encompasses both Criminal History Record Information (CHRI / rap sheets / III data) and operational non-CHRI records (NCIC warrants, protective orders, missing persons, stolen property), requiring strict confidentiality and prohibition from unencrypted public radio broadcast.
  • Version 6.0 reorganized the policy into 20 policy areas aligned with NIST SP 800-53 Rev. 5 control families, including unique credentials, session locks after no more than 30 minutes of inactivity, audit logging, and media sanitization; audits use the v5.9.5 baseline through March 31, 2027 while new controls phase in.
  • Multi-factor authentication (MFA) is required for access to CJI (expanded to all access in v5.9.2, with enforcement beginning October 1, 2024); two passwords count as a single factor, so they do not satisfy the requirement.
  • Personnel security requires state and FBI fingerprint-based background checks before unescorted access (a felony conviction means access is denied unless the CJIS Systems Officer grants a variance), security literacy training before access and annually thereafter, and designated compliance roles such as the Terminal Agency Coordinator (TAC) and Local Agency Security Officer (LASO).
Last updated: September 2026

9.2 CJIS Security Policy: Access Control, MFA & Encryption

Quick Answer: The FBI Criminal Justice Information Services (CJIS) Security Policy sets minimum security requirements for Criminal Justice Information (CJI) handled by public safety agencies and PSAPs. Version 6.0 (December 27, 2024) reorganized the policy into 20 policy areas aligned with NIST SP 800-53 Rev. 5, and version 6.1 (June 25, 2026) is the current release; audits use the v5.9.5 baseline through March 31, 2027 while newer controls phase in. Core requirements include multi-factor authentication for access to CJI, fingerprint-based state and FBI background checks before unescorted access, security literacy training before access and annually, session locks after no more than 30 minutes of inactivity, Physically Secure Locations (PSLs) with escorted visitors, and FIPS-validated encryption (at least 128-bit symmetric keys, with TLS 1.2 or higher in transit). Agencies designate a Terminal Agency Coordinator (TAC) and Local Agency Security Officer (LASO) and maintain formal sanction policies.


1. Statutory Authority, Regulatory Scope & PSAP Classification

The Federal Bureau of Investigation (FBI) Criminal Justice Information Services (CJIS) Division manages the nation's central repositories of criminal history records, fingerprint identification systems, and law enforcement databases. To safeguard this highly sensitive data as it traverses state, regional, and municipal networks, the FBI publishes the CJIS Security Policy (now version 6.x: v6.0 was released December 27, 2024, and v6.1 on June 25, 2026).

                      ┌──────────────────────────────────────────────┐
                      │     FBI CJIS SECURITY POLICY FRAMEWORK       │
                      └──────────────────────┬───────────────────────┘
                                             │
         ┌───────────────────────────────────┼───────────────────────────────────┐
         ▼                                   ▼                                   ▼
[CRIMINAL JUSTICE INFO (CJI)]       [POLICY AREAS]                     [GOVERNANCE & AUDIT]
- Biometric / Biographic Data       - Access Control & MFA             - Terminal Agency Coord (TAC)
- Identity History (CHRI / Raps)    - Physical Protection / PSL         - Local Agency Sec Off (LASO)
- NCIC / Wanted / Protection Orders - Media Sanitization               - Triennial FBI/CSA Audits
- Stolen Property / Vehicle Files   - FIPS-Validated Encryption         - Disciplinary Sanction Policy

Regulatory Jurisdiction Over PSAPs

A common misconception among telecommunicators is that CJIS regulations apply only to police officers or state criminal record bureaus. In reality, any agency—including a municipal 9-1-1 communications center, county consolidated PSAP, or civilian dispatch authority—that accesses, processes, stores, or transmits CJI is legally bound by the FBI CJIS Security Policy.

Because modern CAD and mobile data systems directly interface with state law enforcement message switches, the National Crime Information Center (NCIC), and the International Justice and Public Safety Network (Nlets), the PSAP is classified as a terminal agency. Failure to comply with CJIS mandates can result in severe federal sanctions, including the immediate termination of the agency's direct access to NCIC and state warrant databases, crippling officer safety.

What Constitutes Criminal Justice Information (CJI)?

CJI encompasses any abstract, record, or transmission of information collected by criminal justice agencies that is needed for the administration of criminal justice. CJI is categorized into two primary data classes:

  1. Criminal History Record Information (CHRI): Highly sensitive, legally protected records regarding individuals collected by criminal justice agencies, consisting of identifiable descriptions and notations of arrests, detentions, indictments, formal criminal charges, and final dispositions (convictions, acquittals, sentencing). Commonly referred to as "rap sheets" or Interstate Identification Index (III) data.
  2. Non-CHRI Operations Data: Critical operational records maintained within NCIC and state databases, including:
    • Wanted Persons (felony and misdemeanor warrants)
    • Missing Persons (juveniles, endangered runaways, silver alerts)
    • Protection Orders (domestic violence and restraining orders)
    • Stolen Property (vehicles, license plates, firearms, serialized securities)
    • Threat Actor & Gang Files (violent offenders, known terrorist screenings)

Public Records vs. Protected CJI

Telecommunicators constantly balance public transparency with statutory privacy. While basic CAD incident summaries (such as the time, general location, and nature code of a traffic accident or noise complaint) are generally classified as public records under state Freedom of Information Act (FOIA) laws, CJI and CHRI must never be disclosed to the public. Furthermore, telecommunicators are prohibited from broadcasting unredacted CHRI, complete Social Security numbers, or sensitive NCIC hit returns over unencrypted, public-scanner-accessible radio channels unless an immediate, exigent threat to officer life safety requires it.


2. CJIS Policy Structure: From 13 Policy Areas (v5.9.x) to 20 (v6.x)

For years the CJIS Security Policy was organized into 13 policy areas (version 5.9.x). Version 6.0 (December 27, 2024) restructured it into 20 policy areas that follow the control families of NIST SP 800-53 Rev. 5: Access Control; Awareness and Training; Audit and Accountability; Assessment, Authorization, and Monitoring; Configuration Management; Contingency Planning; Identification and Authentication; Incident Response; Maintenance; Media Protection; Physical and Environmental Protection; Planning; Program Management; Personnel Security; PII Processing and Transparency; Risk Assessment; System and Services Acquisition; System and Communications Protection; System and Information Integrity; and Supply Chain Risk Management. The FBI phases in the new controls by priority, and audits continue against the v5.9.5 requirements through March 31, 2027.

The legacy areas below still appear in many study materials, and their core expectations carry forward into v6.x:

Legacy v5.9.x Policy AreaWhat a PSAP Must Do
1. Information Exchange AgreementsWritten user and management control agreements with the CJIS Systems Agency (CSA), other agencies, and vendors
2. Security Awareness TrainingSecurity literacy training before CJI access and at least annually, plus role-based training for privileged users
3. Incident ResponseA documented capability to detect, report, and track security incidents to the CSA
4. Auditing and AccountabilityLog access to CJI (user, time, action, record) and keep audit records for at least one year
5. Access ControlLeast privilege, account management, and session lock after no more than 30 minutes of inactivity
6. Identification and AuthenticationUnique user IDs (no shared logins) and multi-factor authentication for CJI access
7. Configuration ManagementInventories, secure baselines, and change control for systems that touch CJI
8. Media ProtectionProtect, transport, sanitize, and destroy media containing CJI
9. Physical ProtectionDefine Physically Secure Locations, control visitors, and escort unscreened people
10. System and Communications Protection and Information IntegrityBoundary protection, encryption, malware defense, and patching
11. Formal AuditsTriennial audits by the CSA and the FBI CJIS Division
12. Personnel SecurityFingerprint-based background checks and prompt access removal at transfer or termination
13. Mobile DevicesDevice management, encryption, and remote wipe for mobile devices that access CJI

Exam tip: If a question says "13 policy areas," it is describing the legacy 5.9.x structure. The current policy has 20, but the key operational rules (MFA, training, logging, encryption, background checks) remain.


3. Advanced Authentication (AA) & Multi-Factor Authentication (MFA)

Under its identification and authentication requirements (Policy Area 6 in v5.9.x), the CJIS Security Policy requires multi-factor authentication (MFA), which earlier versions called Advanced Authentication (AA). Passwords alone are recognized as inherently insecure and vulnerable to phishing, keyloggers, and brute-force attacks.

                    MULTI-FACTOR AUTHENTICATION (MFA) ARCHITECTURE
                    (Must combine at least TWO independent factors)
                                           │
         ┌─────────────────────────────────┼─────────────────────────────────┐
         ▼                                 ▼                                 ▼
[SOMETHING YOU KNOW]              [SOMETHING YOU HAVE]              [SOMETHING YOU ARE]
- Complex password / PIN          - Hardware Cryptographic Token    - Biometric Fingerprint Scan
- Alphanumeric passphrase         - PIV / CAC Smart Card            - Iris Pattern Recognition
                                  - Smartphone Authenticator App    - Facial Biometrics
                                  - FIPS-validated PKI Token

The Rule of Two Independent Factors

MFA requires the presentation of at least two different authentication factors drawn from three distinct categories:

  1. Something You Know: A secret memorized value, such as a complex password, passphrase, or PIN.
  2. Something You Have: A physical or cryptographic object in the user's possession, such as a hardware security key (e.g., YubiKey), a Personal Identity Verification (PIV) smart card, a software-based Time-based One-Time Password (TOTP) authenticator app, or a secure cryptographic certificate on a smart badge.
  3. Something You Are: A physical biometric characteristic, such as a fingerprint scan, facial geometry match, or iris pattern.

Compliance Rule: Presenting two passwords (e.g., a Windows login password and a CAD application password) does not constitute MFA—that is merely two instances of "something you know." True MFA must combine factors across distinct categories (e.g., a password combined with a hardware token or fingerprint).

When Is MFA Required?

Earlier versions required advanced authentication mainly when CJI was accessed from outside a Physically Secure Location. Version 5.9.2 (December 2022) expanded the requirement to all access to CJI, with enforcement beginning October 1, 2024, and v6.x keeps it in the Identification and Authentication controls:

  • Remote and mobile access (MDTs in patrol vehicles, laptops, remote administration) requires MFA.
  • Access from inside the dispatch center also requires MFA; working inside a Physically Secure Location no longer removes the requirement.
  • Phishing-resistant authenticators (such as FIDO2 security keys or PKI smart cards) are the stronger choice compared with codes sent by SMS.

4. Personnel Security & Security Awareness Training Mandates

Because people are the most targeted link in the security chain, the policy's Personnel Security and Awareness and Training requirements set firm standards for public safety staffing.

                       PERSONNEL COMPLIANCE TIMELINE

  Before Access (Pre-Hire)  ──► State & FBI Fingerprint-Based Background Check
                                (Felony = access denied unless the CSO grants a variance)
                                       │
  Before CJI Access         ──► Security Literacy Training Completed
                                (Plus role-based training for privileged users)
                                       │
  Every Year (Annual)       ──► Refresher Security Literacy Training
                                (Continuous requirement throughout employment)
                                       │
  Termination / Resignation ──► Prompt Revocation of All Logical & Physical Access

1. Fingerprint-Based Background Screening

Prior to being granted unescorted physical access to a dispatch floor or logical access to systems containing CJI:

  • Every employee, telecommunicator, administrative staff member, IT technician, and external vendor contractor must submit to a comprehensive state and national 10-fingerprint-based criminal background check processed through the state CSA and the FBI.
  • Felony Convictions: If the record check shows a felony conviction, access to CJI is denied; the state CJIS Systems Officer (CSO) may review the circumstances and grant a variance.
  • Misdemeanor Records: Misdemeanor convictions (especially those involving theft, fraud, computer crimes, or moral turpitude) are subject to strict administrative review. The state CJIS Systems Officer (CSO) or local agency executive must formally evaluate the record and execute a written determination of suitability.

2. Mandatory Security Awareness Training Intervals

The CJIS Security Policy establishes precise, audited timelines for staff training:

  • Before Access: Security literacy training must be completed before a person receives access to CJI (older 5.x versions allowed up to six months after assignment).
  • Annual Refresher: Training is repeated at least annually and after significant system or policy changes (older 5.x versions used a two-year cycle).
  • Curriculum: Training must cover social engineering risks, phishing recognition, password hygiene, workstation physical security, clean desk policies, visitor escort rules, and the legal consequences of unauthorized CJI dissemination. All training completion certificates must be archived for state audit inspection.

5. Physical Protection: The Physically Secure Location (PSL) & Media Destruction

Under Policy Area 9, any physical space where CJI is accessed, processed, displayed, or discussed must be formally designated as a Physically Secure Location (PSL).

                       PHYSICALLY SECURE LOCATION (PSL) PERIMETER

       [ Public Lobby / Exterior ]
                   │
                   ▼  (Locked Access-Controlled Door / Keycard / Biometrics)
       ┌───────────────────────────────────────────────────────────────────┐
       │                    PHYSICALLY SECURE LOCATION                     │
       │                                                                   │
       │  [Dispatch Consoles]             [CAD / Server Racks]             │
       │  - Screens angled from windows   - Keycard-locked cages           │
       │  - Privacy filters installed     - Video surveillance monitored   │
       │                                                                   │
       │  [VISITOR ESCORT MANDATE]                                         │
       │  - Non-cleared staff (HVAC, janitors) escorted 100% of the time   │
       │  - Formal Visitor Log: Name, agency, date, time-in, time-out,     │
       │    photo ID checked, designated escort signature                  │
       └───────────────────────────────────────────────────────────────────┘

Perimeter Security Controls & Clean Screen / Desk Policy

A PSL (such as the 9-1-1 dispatch floor, radio communications room, or central server vault) must possess a hardened physical perimeter:

  • Perimeter Access: External doors must remain closed and locked 24/7/365, accessible only via authorized electronic keycards, cryptographic RFID badges, or biometric access scanners.
  • Prominent Signage: Entry doors must display clear, prominent physical signs stating: "Restricted Area – Authorized Personnel Only – Criminal Justice Information System."
  • Screen Privacy & Clean Desk Rules: Dispatch monitors displaying CAD records, warrants, or NCIC data must be physically positioned away from exterior windows, visitor viewing galleries, or lobby glass. If physical repositioning is impossible, monitors must be fitted with polarized privacy filters to prevent visual eavesdropping ("shoulder surfing"). Under agency clean desk policies, telecommunicators must immediately lock workstation screens when stepping away from the console and place printed incident records into locked storage bins.

Visitor Access Controls & Escort Logs

Public safety facilities frequently require visits from non-cleared personnel—including commercial janitorial crews, HVAC repair technicians, electrical contractors, equipment delivery drivers, and visiting elected officials:

  • Continuous Physical Escort: Any individual who has not successfully completed a 10-fingerprint state and FBI background clearance must be accompanied by an authorized, cleared agency escort at all times while inside the PSL.
  • The Formal Visitor Log: The agency must maintain a physical or electronic visitor log at every PSL entry point. The log must record:
    1. Visitor's full legal name
    2. Organization or commercial company represented
    3. Date of visit
    4. Exact time of arrival (time in)
    5. Exact time of departure (time out)
    6. Verification of government-issued photo ID (driver's license or passport)
    7. Name and badge number of the authorized employee serving as the escort
  • Visitor logs must be retained for compliance auditing and presented during triennial CJIS audits.

Media Sanitization Standards (Policy Area 8)

When disposing of physical or digital media containing CJI:

  • Physical Media (Paper Records): Printed warrant abstracts, teletype sheets, and criminal history printouts are kept in locked bins and destroyed by shredding or incineration, carried out or witnessed by authorized personnel. Agencies commonly choose cross-cut shredders because strip-cut paper can be reconstructed.
  • Electronic Media (Hard Drives, SSDs, Backup Tapes): Storage devices are sanitized before reuse or disposal (overwriting, cryptographic erase, or degaussing, consistent with NIST SP 800-88) or physically destroyed, and the agency keeps records of the media, the method, and the authorized personnel involved.

6. Federal Cryptographic Standards: FIPS 140-2 / FIPS 140-3 Encryption

Under the system and communications protection requirements (Policy Area 10 in v5.9.x), CJI transmitted or stored outside a Physically Secure Location must be protected with FIPS-validated encryption.

                   FEDERAL ENCRYPTION COMPLIANCE ARCHITECTURE
                                       │
         ┌─────────────────────────────┴─────────────────────────────┐
         ▼                                                           ▼
[DATA IN TRANSIT]                                           [DATA AT REST]
- Traversing public/untrusted networks                      - Stored outside a PSL (MDTs, laptops,
- Cellular MDT connections, WAN links, VPNs                   cloud storage, USB backup drives)
- Minimum 128-bit AES symmetric key                         - Minimum 128-bit AES full-disk encryption
- FIPS 140-3 (or current 140-2) Validated                   - FIPS 140-3 (or current 140-2) Validated  
- TLS 1.2 or higher, or IPsec tunnel                        - BitLocker / LUKS with FIPS mode active

The FIPS Validation Requirement

A commercial software vendor cannot simply claim to use "military-grade 256-bit encryption." Under CJIS policy, the underlying cryptographic module implementing the encryption must be validated through NIST's Cryptographic Module Validation Program under FIPS 140-3, the successor to FIPS 140-2 (whose remaining certificates move to NIST's historical list in September 2026, so new purchases should rely on FIPS 140-3 validations).

Encryption in Transit

Whenever CJI traverses a network outside the physical boundaries of a PSL—including public internet circuits, municipal wide area networks (WANs), commercial microwave backhauls, or cellular connections feeding police MDTs:

  • The data stream must be encapsulated in an encrypted tunnel (e.g., IPSec VPN or TLS 1.2 / TLS 1.3).
  • The symmetric encryption algorithm must utilize a minimum key length of 128-bit Advanced Encryption Standard (AES). AES-256 is widely recommended.

Encryption at Rest

Any electronic device that stores CJI outside a Physically Secure Location must implement full-disk encryption (FDE) using FIPS 140-2/3 validated minimum 128-bit AES:

  • Applies to mobile data computers, investigator laptops, cellular tablets, and external USB backup drives.
  • Lost or Stolen Devices: Encryption protects CJI on a stolen MDT or laptop, but the loss is still a security incident that must be reported and handled under the agency's incident response procedures, including remote wipe where available.

7. Administrative Oversight: TAC, LASO, Triennial Audits & Sanction Policies

Administrative oversight within the PSAP is anchored by institutional compliance roles, recurring audits, and enforceable employee sanctions.

The Terminal Agency Coordinator (TAC) & Local Agency Security Officer (LASO)

Every public safety agency that operates a terminal accessing NCIC or state criminal justice databases must formally designate two key compliance officials:

  • Terminal Agency Coordinator (TAC): Serves as the primary administrative and operational liaison between the local PSAP and the state CJIS Systems Agency (CSA) / CJIS Systems Officer (CSO). The TAC oversees user account provisioning, role-based authorizations, immediate credential revocations upon staff termination, annual training tracking, fingerprint records, and triennial audit preparation.
  • Local Agency Security Officer (LASO): Appointed to oversee technical information security. The LASO monitors technical compliance with the policy's security controls, ensures security patches and firewalls are properly maintained, investigates potential security breaches, and coordinates technical incident reporting to the CSA.

Triennial CJIS Compliance Audits

At least once every three years (triennially), the state CSA and the FBI CJIS Audit Unit conduct a comprehensive on-site compliance audit of the PSAP:

  • Technical Review: Auditors inspect network topology diagrams, firewall rule sets, FIPS encryption certificate numbers, MFA configurations, and system audit logs.
  • Physical Inspection: Auditors inspect the facility perimeter, verify door locking mechanisms, examine CAD screen visibility from windows, review visitor escort logs, and inspect media destruction bins.
  • Personnel Audit: Auditors review personnel rosters against fingerprint submission dates and verify that every telecommunicator completed security training within the required intervals.

Mandatory Sanction Policies & Penalties for Misuse

The CJIS Security Policy requires every criminal justice agency to establish and enforce a written employee sanction policy governing violations of security rules:

  • Unauthorized Inquiries ("Curiosity Queries"): A telecommunicator who runs a warrant check, license plate query, or criminal history on a neighbor, romantic partner, celebrity, or family member has committed a severe security violation.
  • Graduated Sanctions: Agency policy must outline progressive discipline, ranging from formal written reprimand, mandatory retraining, and administrative suspension, up to immediate termination of employment.
  • Criminal Prosecution: Willful misuse, unauthorized disclosure, or selling of Criminal Justice Information is a criminal offense under state and federal computer crime statutes (e.g., the Computer Fraud and Abuse Act), punishable by fines and imprisonment.

8. Operational Traps & ENP Exam Watch

  • Training Timing Changed: Current CJIS policy requires security literacy training before CJI access and annually thereafter. The older "within six months, then every two years" rule comes from earlier 5.x versions.
  • Triennial Audit Cycle: CJIS compliance audits occur on a triennial (every 3 years) cycle, not annually or every five years.
  • Two Passwords Do Not Equal MFA: Remember that Multi-Factor Authentication requires two different types of factors (Knowledge, Possession, Biometric). Combining a domain password with an application password is two instances of "something you know" and does not satisfy CJIS MFA requirements.
  • Unescorted Visitors are NEVER Permitted: Even long-term trusted maintenance workers, city janitors, or HVAC technicians must be continuously escorted unless they have undergone a formal 10-fingerprint state and FBI background check. Length of municipal service never excuses the lack of background clearance.
  • The 30-Minute Session Lock: Devices accessing CJI must lock after no more than 30 minutes of inactivity (agencies may set shorter timeouts), requiring re-authentication. The policy exempts certain dispatch terminals located inside a Physically Secure Location.
Test Your Knowledge

Under the current FBI CJIS Security Policy, when must personnel with access to Criminal Justice Information (CJI) complete security literacy (awareness) training?

A
B
C
D
Test Your Knowledge

Under the current FBI CJIS Security Policy, when is multi-factor authentication (MFA) required?

A
B
C
D
Test Your Knowledge

In a Public Safety Answering Point (PSAP) operating as a criminal justice terminal agency, what is the primary role of the designated Terminal Agency Coordinator (TAC)?

A
B
C
D