Skip to content

Resource

CJIS Compliance: What It Actually Requires, and What It Requires From Your IT Provider

Most explanations of CJIS compliance stop at the agency. The part that gets agencies in trouble is the other half: every vendor with access to criminal justice information is in scope too, and the agency is accountable for whether that vendor actually meets the standard.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting

What CJIS compliance is

The CJIS Security Policy is the FBI's set of minimum security requirements for anyone who accesses, stores, processes, or transmits criminal justice information. It covers the obvious systems (records management, dispatch, state and federal query systems) and a lot of things agencies do not think of as criminal justice systems at all, including the backups those systems write to, the email that carries case information, and the laptop in a patrol vehicle.

The policy is set federally and enforced through each state's CJIS Systems Agency. In Pennsylvania that role sits with the Pennsylvania State Police, and access runs through CLEAN, the Commonwealth Law Enforcement Assistance Network. Each agency designates a Terminal Agency Coordinator who is the practical point of contact for access, training records, and audit preparation. The requirements have been moving steadily toward alignment with the federal NIST control catalog, which in practice means more documentation and more evidence rather than fewer controls.

The half most agencies miss: your vendors are in scope

If a private contractor can reach criminal justice information, that contractor is inside the boundary. The mechanism is the CJIS Security Addendum, a standard agreement the vendor signs that binds its personnel to the same rules agency staff follow. Signing it is not a formality. It means the vendor's employees go through the same screening, the same training cycle, and the same access discipline.

The accountability does not transfer with the work. If a vendor's technician was never screened, or a support tool gave remote access to someone outside the boundary, that is the agency's finding to answer for. This is why price alone is a bad way to choose an IT provider for an agency. The cheapest bid is often the one that has not absorbed the cost of screening its staff.

The control areas that matter in practice

  • Personnel screening. Fingerprint based background screening before access is granted, for every person who can reach criminal justice information, including contractors and anyone providing remote support.
  • Security awareness training. Role-appropriate training completed on a defined schedule, with records that can be produced on request.
  • Individual identities and advanced authentication. No shared accounts. Multi-factor or equivalent authentication, which applies to mobile data terminals in vehicles exactly as it applies to a desk in the station.
  • Encryption. FIPS validated encryption for criminal justice information in transit and at rest, which is a narrower requirement than simply having encryption turned on.
  • Audit logging. Logs that record who accessed what and when, retained long enough to be useful, and actually reviewed rather than just generated.
  • Incident response. A documented plan with defined reporting obligations and timelines, tested rather than filed.
  • Configuration and patch management. Known configurations, applied patches, and a record of both.
  • Physical protection and media handling. Controlled physical access to equipment, and defined destruction and sanitization for drives and media that held criminal justice information.
  • Network boundaries. Criminal justice systems separated from general municipal operations, with the separation documented and verified rather than assumed.

What an audit is actually looking for

Audits generally run on a roughly three year cycle, and the thing that determines the outcome is whether evidence exists. Not whether the agency intends to meet the standard, and not whether the technology is capable of meeting it. Whether someone can produce the artifact.

In practice that means a current list of who has access and when it was last reviewed, screening records for every person on that list including vendor staff, training completion records, the encryption configuration in place, log retention settings, the incident response plan and evidence it has been exercised, and the signed addendums for every vendor in the boundary. Agencies that struggle are almost never agencies with bad technology. They are agencies where the controls exist and nobody wrote any of it down.

Five questions to ask an IT provider before you sign

  • Which of your technicians are screened, and can you show me the records? The right answer is all of them, with documentation. A provider that screens case by case will slow down every project.
  • Will you sign the CJIS Security Addendum? A provider that hesitates here is telling you they have not done this before.
  • How do your remote support tools handle access, and are those sessions logged? Remote support is the most common way an unscreened person ends up inside the boundary.
  • What documentation will you maintain for our audit, and will you hand it to us or make us assemble it? Evidence produced continuously is a different service than evidence assembled in a panic.
  • How do you separate our police network from the rest of our operations, and how do you verify it stayed separated? Segmentation that was correct at setup and never checked again is one of the most common findings.

Where CJIS sits next to HIPAA and CMMC

Agencies often carry more than one obligation at once. A county with a health function has HIPAA in the mix. A municipality bidding on defense related work may run into CMMC. The frameworks differ in what they protect and who enforces them, but the underlying controls overlap heavily, which means a single documented baseline can usually satisfy the common ground and let you handle the differences at the edges. We cover how the three compare in HIPAA, CJIS and CMMC compliance explained.

What this looks like for a small agency

Most municipal police departments do not have dedicated IT staff. The work falls to whoever is most comfortable with computers, plus a vendor who handles the server. That arrangement can meet the standard, but only if someone is deliberately maintaining the evidence, and that is usually the part nobody owns.

The practical fix is not more technology. It is deciding who is responsible for each control, writing down what is in place, and reviewing it on a schedule instead of before an audit. An agency that does that has a manageable audit. An agency that does not has a project every three years.

Common questions

Questions leadership usually asks first.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.