Back to blog
US & Americas

CJIS Security Policy: what contractors handling criminal justice data must do

Any organisation touching criminal justice information inherits a prescriptive control set, personnel screening obligations and audit exposure - usually through a contract with an agency.
GRC Copilot Team
CJIS Security Policy: what contractors handling criminal justice data must do

Most organisations encounter the CJIS Security Policy the way they encounter every other government control set - through a contract. A software vendor, cloud provider or service supplier to a law enforcement agency inherits obligations over criminal justice information, and those obligations are unusually prescriptive.

What is in scope

Criminal justice information - data derived from criminal history records, biometric records, case and incident histories and related information. If your system stores, processes or transmits it, or if your staff can access it, you are in scope. That includes support engineers with production access, which is the route most vendors overlook.

The control areas

The policy is organised into policy areas covering information exchange agreements, security awareness training, incident response, auditing and accountability, access control, identification and authentication, configuration management, media protection, physical protection, systems and communications protection, formal audits, personnel security, and mobile devices.

The substance overlaps heavily with any modern security programme. What differs is prescriptiveness and a few specific requirements that catch vendors out.

The requirements that catch vendors out

  • Advanced authentication - multi-factor is required for access from outside a physically secure location, with specific expectations about what counts.
  • Personnel screening - fingerprint-based background checks for anyone with access, including contractors and support staff. This is a hiring and onboarding process change, not a technical control.
  • Encryption requirements with specified strength for data in transit and at rest, and validated cryptographic modules.
  • Physical security of any location where the data is accessed, which reaches into home working arrangements.
  • Audit trail retention for a defined minimum period.
  • Incident reporting to the agency within defined timelines.
  • Media sanitisation and disposal with records.
Personnel screening is the obligation most often discovered late. It applies to people, takes time, and cannot be retrofitted quickly before an audit - and it constrains where you can staff support from.

Map a prescriptive control set to what you already run

GRC Copilot maps one control library across sector-specific and international frameworks so overlapping requirements are evidenced once.

Cloud and offshore constraints

Using cloud services is permitted, subject to the provider meeting the requirements and appropriate agreements being in place - which is why major providers offer government-specific environments. Restrictions on access from outside the United States are a live consideration for any vendor with offshore support or development teams, and they frequently reshape the delivery model rather than just the controls.

Audits

Agencies are audited on a cycle, and their vendors are examined as part of that. Expect to evidence: signed agreements, screening records for every individual with access, training completion, access reviews, audit log retention, encryption configuration and incident records.

Relationship to other frameworks

An organisation running ISO 27001 or aligned to NIST SP 800-53 will find most control substance already present. The delta is the prescriptive specifics - advanced authentication, fingerprint-based screening, validated cryptography, geographic restrictions and the agreement paperwork. Map onto your existing control set rather than building a parallel programme.

Frequently asked questions

Does it apply to us as a vendor?

If your people or systems can access criminal justice information, yes - through your contract with the agency. Read the security schedule.

Do support engineers need background checks?

If they can access the data, generally yes. This is the requirement most often discovered late.

Can we use public cloud?

Yes, with a compliant provider and appropriate agreements. Verify the specific service and region rather than a provider-wide claim.

Does ISO 27001 cover it?

It covers much of the substance and not the prescriptive specifics or the screening and agreement obligations.

Key takeaways

  • Obligations arrive through agency contracts, not direct regulation.
  • Fingerprint-based personnel screening is the long-lead item.
  • Geographic access restrictions can reshape your support model.
  • Map onto an existing programme; the delta is prescriptive detail.
#cjis #criminal-justice #law-enforcement #advanced-authentication #personnel-screening #audit