FBI Criminal Justice Information Services Security Policy
Security policy for all entities accessing FBI Criminal Justice Information (CJI). Applies to law enforcement agencies, contractors, and any organization with CJI access.
What CJIS draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Auditable Events
Systems MUST generate audit records for successful and unsuccessful access attempts to CJI.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Content of Audit Records
Audit records MUST contain date/time, component, type of event, user identity, and outcome.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Audit Monitoring and Review
Agency MUST implement procedures for monitoring and analyzing audit records to detect inappropriate activity.
Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.
Audit Record Retention
Audit records MUST be retained for a minimum of one year and available for review.
Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.
What CJIS covers
CJIS Security Policy, Sec. 4 — Criminal Justice Information
Criminal justice information — the data provided by the FBI CJIS systems, needed by law enforcement to perform its mission.
In scope
- Biometric, identity history, biographic and property data
- Case and incident history
Criminal history record information (CHRI)
The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.
- Arrests, detentions, indictments and dispositions
- Sentencing, correctional supervision and release information
CHRI is the sub-category that drives the access, audit and personnel-screening controls. Treating all CJI as one class over-applies the strictest requirements and is a common cause of failed audits.
FBI CJIS Security Policy · as at 2026-08
How CJIS is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The FBI CJIS Division, through the state CJIS Systems Agency.
CJIS enforcement runs through audit and access rather than money. Findings produce corrective action; unresolved or serious findings suspend and then terminate the agency access to the national systems, which stops queries an operational unit depends on. Misuse of criminal justice information is separately a criminal matter in most states.
State law, not the CJIS Security Policy, supplies the criminal offence for misuse, so the exposure varies by state.
Uncapped exposure that sits outside this instrument
These come from company law rather than from CJIS, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for CJIS,
not configured for it afterwards
CJI Access Monitoring
Track all access to Criminal Justice Information databases
CJIS Audit Trail Report
Complete access history with success/failure status
CJI Data Patterns
Identify criminal history, warrants, and law enforcement data
Unauthorized CJI Access
Alert on access attempts outside authorized parameters
Other Government frameworks
Walk into the CJIS audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.