CJISGovernmentUnited StatesLaw Enforcement

FBI Criminal Justice Information Services Security Policy

Security policy for all entities accessing FBI Criminal Justice Information (CJI). Applies to law enforcement agencies, contractors, and any organization with CJI access.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

CJIS5.4.1.1A record of access

Auditable Events

Systems MUST generate audit records for successful and unsuccessful access attempts to CJI.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

CJIS5.4.1.2A record of access

Content of Audit Records

Audit records MUST contain date/time, component, type of event, user identity, and outcome.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

CJIS5.4.3Spotting the abnormalA record of access

Audit Monitoring and Review

Agency MUST implement procedures for monitoring and analyzing audit records to detect inappropriate activity.

Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.

CJIS5.4.6Retention and availability

Audit Record Retention

Audit records MUST be retained for a minimum of one year and available for review.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

What CJIS covers

CJIS Security Policy, Sec. 4 — Criminal Justice Information

Criminal justice information — the data provided by the FBI CJIS systems, needed by law enforcement to perform its mission.

In scope

  • Biometric, identity history, biographic and property data
  • Case and incident history

Criminal history record information (CHRI)

The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.

  • Arrests, detentions, indictments and dispositions
  • Sentencing, correctional supervision and release information

CHRI is the sub-category that drives the access, audit and personnel-screening controls. Treating all CJI as one class over-applies the strictest requirements and is a common cause of failed audits.

FBI CJIS Security Policy · as at 2026-08

How CJIS is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The FBI CJIS Division, through the state CJIS Systems Agency.

CJIS enforcement runs through audit and access rather than money. Findings produce corrective action; unresolved or serious findings suspend and then terminate the agency access to the national systems, which stops queries an operational unit depends on. Misuse of criminal justice information is separately a criminal matter in most states.

State law, not the CJIS Security Policy, supplies the criminal offence for misuse, so the exposure varies by state.

Uncapped exposure that sits outside this instrument

These come from company law rather than from CJIS, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for CJIS,
not configured for it afterwards

Policy Template

CJI Access Monitoring

Track all access to Criminal Justice Information databases

Report

CJIS Audit Trail Report

Complete access history with success/failure status

Classification

CJI Data Patterns

Identify criminal history, warrants, and law enforcement data

Alert

Unauthorized CJI Access

Alert on access attempts outside authorized parameters

Walk into the CJIS audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment