Resource
CJIS Readiness Checklist
A readiness checklist for Pennsylvania municipalities, police departments, and their IT providers, written against CJIS Security Policy v6.1.
What the checklist covers.
The checklist walks through the areas a CJIS audit looks at: agreements, personnel, access, encryption, physical security, systems, logging and incident response, Microsoft 365, cloud, and AI tools.
It is written for the agency and for the IT provider together, because a vendor with access to criminal justice information is inside the compliance boundary too. For the full explanation of each requirement, read our guide to CJIS compliance requirements.
Use it before the audit, not during it.
Work through it with whoever owns IT for your agency and mark what is in place, what is partly in place, and what nobody owns yet. The gaps you find are the list to work on before the next audit cycle.
The checklist also recommends a written AI acceptable use policy. If you do not have one, our AI acceptable use policy guide is a good place to start. For how we support agencies directly, see our IT support for local government and police departments.
The checklist
Download the CJIS Readiness Checklist.
Agreements, personnel, access, encryption, physical security, systems, logging and incident response, Microsoft 365, cloud, and AI tools, in one printable PDF. Free to download, no email required.
Common questions
Questions leadership usually asks first.
Continue reading
Related work and reading.
CJIS Compliance Requirements for IT Providers
The detailed requirements for agencies and every vendor with access to criminal justice information.
Read more: CJIS Compliance Requirements for IT ProvidersIT Support for Local Government and Police Departments
All 3rd Element staff are CJIS cleared.
Read more: IT Support for Local Government and Police DepartmentsAI Acceptable Use Policy
The written AI policy the checklist recommends, and what it should cover.
Read more: AI Acceptable Use PolicyIT Environment Review
Free, 30 minutes, video or phone, with a written summary afterward.
Read more: IT Environment ReviewNext step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
