What CJIS is, in plain terms
The FBI Criminal Justice Information Services (CJIS) Division publishes the CJIS Security Policy — the set of controls that protects Criminal Justice Information (CJI) wherever it's stored, transmitted, or accessed. CJI includes NCIC query data, state criminal-history records, fingerprint-based background-check data, and anything the FBI defines as criminal justice information.
Any agency that touches CJI — through NCIC, through a state system that feeds NCIC, through a records management system that pulls CJI, through a CAD that connects to dispatch — has to meet the policy. That includes the smallest rural police department, the smallest sheriff's office, the municipality's records clerk who runs background checks.
The 13 policy areas
- Information exchange agreements. Written agreements with every entity exchanging CJI with the agency. The MSP contract needs the CJIS Security Addendum.
- Security awareness training. Annually for every person with CJI access — sworn officers, civilian dispatchers, records staff, IT support. Documented, with completion records.
- Incident response. Written plan, table-top exercise annually, breach-notification process to the state's CJIS Systems Officer (CSO).
- Audit and accountability. Audit logging on every CJI-accessing system, retained per §5.4 (often longer than agencies are configured for), reviewed.
- Access control. Least-privilege on every account, separation of duties where staffing allows, session timeouts, account-management procedures.
- Identification and authentication. Advanced authentication (CJIS-grade MFA) on every CJI-accessing account, with FIPS-validated authenticators. The detail here matters — some MFA products are not FIPS-validated.
- Configuration management. Documented baseline configurations, change control, vulnerability management.
- Media protection. Encryption of CJI on portable media; secure disposal of media that held CJI.
- Physical protection. CJI workstations in physically secured spaces, with documented access controls.
- System and communications protection. FIPS-validated encryption (AES) of CJI at rest and in transit. Network segmentation between CJI-accessing systems and the rest of the agency network.
- Formal audits. Triennial CJIS audit by the state CSO, plus internal annual audits.
- Personnel security. Fingerprint-based background check on everyone with CJI access — including IT support staff, including remote support technicians. Documented.
- Mobile devices. Specific controls on phones, tablets, and laptops that touch CJI — encryption, remote wipe, container separation.
What an MSP can own (and what stays with the agency)
An MSP serving a CJIS environment owns the technical work: the FIPS-validated MFA, the encryption configuration, the audit-log infrastructure, the patching cadence, the EDR, the SOC, the segmented network, the media-encryption tooling. The MSP also signs the CJIS Security Addendum, completes the CJIS security awareness training annually, and submits MSP staff with CJI access for the agency's fingerprint-based background check.
The agency owns the policy work: designating the Local Agency Security Officer (LASO), maintaining the written policies, conducting the annual training for sworn and civilian staff, the physical-security work on the building, the personnel decisions, and the relationship with the state CJIS Systems Officer.
The audit, in practice
Triennial CJIS audits from the state CSO are the formal review. They typically ask for:
- The current Information Exchange Agreement and CJIS Security Addendum.
- Training completion records for every person with CJI access, current year.
- Fingerprint-based background check documentation for every person with CJI access, current.
- The MFA configuration evidence — product, FIPS validation status, coverage report.
- The encryption configuration evidence — at-rest and in-transit, FIPS validation status.
- The audit-log retention configuration and a sample of recent logs.
- The written incident-response plan plus the last table-top exercise.
- The configuration baseline documents and the change-management records.
- The patching SLA evidence.
- The network diagram showing CJI segmentation.
If those ten documents are organized in one folder and current, the audit is a one-meeting conversation. If they're not, it's several meetings of getting them in order.
The three most common audit findings
- MFA gaps. Either MFA isn't deployed on every CJI-accessing account, or it's deployed using a product that's not FIPS-validated. CJIS requires FIPS validation for advanced authenticators — specific Microsoft Authenticator configurations qualify, generic SMS often doesn't, and not every TOTP app qualifies.
- Audit-log retention. The retention configured on the system is shorter than CJIS Policy §5.4 requires. Often Windows event logs default to a small ring buffer that overwrites within weeks; CJIS expects retention measured in years.
- Personnel security on IT support staff. The agency has fingerprint-based background checks for sworn and civilian agency staff, but not for the MSP's remote-support technicians who can RDP into CJI workstations. CJIS expects the same screening for anyone with logical access.
Mobile devices and CJI
The mobile-device policy area (CJIS §5.13) has specific controls when an officer's phone or in-car laptop touches CJI. Required: agency-configured encryption, remote wipe capability, container or workspace separation of CJI from personal data, screen-lock requirements, and access controls. Personal devices with CJI access are generally not acceptable; either the agency issues the device or the BYOD policy meets every §5.13 requirement (rare).
How a Micro-IT engagement works for CJIS-scoped agencies
Municipal clients with a CJI-accessing department (police, sheriff, dispatch) get the standard managed stack with CJIS-specific configuration: FIPS-validated Microsoft Authenticator MFA on every CJI account, FIPS-validated encryption at rest and in transit, segmented network on the Ubiquiti / Unifi stack with documented VLAN structure, audit-log retention configured to CJIS requirements, and the SOC's incident-response runbook updated for CJIS breach-notification flow. The CJIS Security Addendum is signed on contract day. MSP staff with CJI access complete the agency's security awareness training and are submitted for fingerprint-based background checks. See the municipal IT page for the full vertical posture.
