Exhibit_G_-_CJIS_Security_Policy_v6-0_20241227.pdf

PDF 4 MB Posted

Attached to
Jail Management System (JMS) State and local contract opportunity
Solicitation number
25-P-147JRD
Issued by
Volusia County, Florida

About this file

CJIS Security Policy Version 6.0 and Volusia County Jail Management System Procurement Summary

This document is the Criminal Justice Information Services (CJIS) Security Policy Version 6.0, issued by the Federal Bureau of Investigation (FBI) CJIS Division, dated December 27, 2024, which establishes mandatory security requirements for all criminal justice agencies, noncriminal justice agencies, and interface agencies accessing FBI criminal justice information systems. The policy applies to all state, local, tribal, territorial, and federal agencies processing, storing, or transmitting criminal justice information (CJI), and establishes a shared management philosophy among the FBI CJIS Division, CJIS Systems Agencies (CSAs), State Identification Bureaus (SIBs), and Interface Agencies (IAs). The CJISSECPOL provides baseline security controls across 21 policy areas including access control, identification and authentication, system and communications protection, personnel security, and supply chain risk management, with implementation requirements designated as Priority 1 (sanctionable requirements effective October 1, 2024), Priority 2-4 (falling into zero-cycle status through September 30, 2027), or Existing requirements. The policy modernization represents the completion of the Security Policy Modernization Task Force initiative, incorporating updated controls for authenticators, system and services acquisition, supply chain risk management, personnel security, assessment and authorization, and monitoring, with the policy publicly available for distribution without restrictions.

Volusia County, Florida, Division of Corrections seeks a comprehensive Jail Management System (JMS) through RFP #25-P-147JRD to manage its jail operations including inmate data, security rounds, head counts, and receivables tracking for approximately 320 correctional officers serving an average daily population of 1,345 inmates. The system must be modular, web-based, and mobile-enabled, supporting 300 concurrent users and 600 named users with integration capabilities to 22 external agency systems and third-party platforms including medical records, banking, visitation, and notification services. Bidders must submit proposals by October 9, 2025, with a pre-proposal meeting scheduled for September 5, 2025, and questions due by September 25, 2025; evaluation will score firm qualifications (20%), price schedules (10%), software capabilities (25%), project understanding (15%), technology (20%), and maintenance and warranty (10%). The contract includes an initial five-year term with options for two subsequent three-year renewals, with implementation targeted for completion by May 25, 2026. Respondents must provide references from facilities with at least 800 beds (preferably in Florida) and demonstrate at least five years of operational experience in jail management systems; the current environment includes approximately 80 BizTalk orchestrations, 36 XML-based data exchanges, and 41 message queues, and the system must achieve full compliance with CJIS security requirements as established in the FBI's security policy.

View the file

Other files for this state and local contract opportunity

Other files attached to Jail Management System (JMS), newest first.
File Type Posted
Jail_Management_System_(JMS)_(Addendum_#5_Revision).pdf PDF
Jail_Management_System_(JMS)_(Addendum_#5_Revision).pdf PDF
Exhibit_I_-_Sample_Agreement_-_version_2.pdf PDF
Exhibit_A.10_Version2_-_JMS_Exchanges_25-P-147JRD.pdf PDF
Exhibit_A.10_Version2_-_JMS_Exchanges_25-P-147JRD.pdf PDF
Exhibit_A.9_Version2_-_JMS_Interfaces_25-P-147JRD.pdf PDF
Exhibit_A.9_Version2_-_JMS_Interfaces_25-P-147JRD.pdf PDF
Exhibit_A.5_Version2_-_JMS_Interfaces_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.5_Version2_-_JMS_Interfaces_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_I_-_Sample_Agreement.pdf PDF
Exhibit_E_-_Business_Associate_Agreement_DRAFT_25-P-147JRD.pdf PDF
Exhibit_F_-_County_Computing_Security_Procedures_25-P-147JRD.pdf PDF
Exhibit_D_-_Technology_Systems_Design_and_Installation_Guidelines_(Division_27)_25-P-147JRD.pdf PDF
Exhibit_G_-_CJIS_Security_Policy_v6-0_20241227.pdf PDF
Exhibit_H_-_Acceptance_Form_25-P-147JRD.pdf PDF
Exhibit_E_-_Business_Associate_Agreement_DRAFT_25-P-147JRD.pdf PDF
Exhibit_H_-_Acceptance_Form_25-P-147JRD.pdf PDF
Exhibit_G_-_CJIS_Security_Policy_v6-0_20241227.pdf PDF
Exhibit_B_-_JMS_Price_Schedule.xls XLS spreadsheet
Exhibit_C_-_Technical_Infrastructure_Standards_25-P-147JRD.pdf PDF
Exhibit_E_-_Business_Associate_Agreement_DRAFT_25-P-147JRD.pdf PDF
Exhibit_F_-_County_Computing_Security_Procedures_25-P-147JRD.pdf PDF
Exhibit_D_-_Technology_Systems_Design_and_Installation_Guidelines_(Division_27)_25-P-147JRD.pdf PDF
Exhibit_H_-_Acceptance_Form_25-P-147JRD.pdf PDF
Exhibit_B_-_JMS_Price_Schedule.xls XLS spreadsheet
Exhibit_A_-_JMS_Scope_of_Work_25-P-147JRD.pdf PDF
Exhibit_A_-_JMS_Scope_of_Work_25-P-147JRD.pdf PDF
Exhibit_A_-_JMS_Scope_of_Work_25-P-147JRD.pdf PDF
Exhibit_A.2_-_JMS_Technical_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.2_-_JMS_Technical_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.2_-_JMS_Technical_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.12_-_JMS_Reports_and_Extracts_redacted.pdf PDF
Exhibit_A.11_-_JMS_Third_Party_Software_25-P-147JRD.pdf PDF
Exhibit_A.8_-_JMS_Reports_and_Extracts_Requirements_Matrix.xlsx XLSX spreadsheet
Exhibit_A.9_-_JMS_Interfaces_25-P-147JRD.pdf PDF
Exhibit_A.8_-_JMS_Reports_and_Extracts_Requirements_Matrix.xlsx XLSX spreadsheet
Exhibit_A.11_-_JMS_Third_Party_Software_25-P-147JRD.pdf PDF
Exhibit_A.11_-_JMS_Third_Party_Software_25-P-147JRD.pdf PDF
Exhibit_A.1_-_JMS_Functional_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.5_-_JMS_Interfaces_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.6_-_JMS_Exchanges_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.4_-_JMS_Server_Environment_Worksheet_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.3_-_JMS_Technical_Requirements_Form_25-P-147JRDL.doc DOC document
Exhibit_A.1_-_JMS_Functional_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.4_-_JMS_Server_Environment_Worksheet_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.7_-_JMS_Third_Party_Software_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.1_-_JMS_Functional_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.7_-_JMS_Third_Party_Software_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Exhibit_A.3_-_JMS_Technical_Requirements_Form_25-P-147JRDL.doc DOC document
Exhibit_A.7_-_JMS_Third_Party_Software_Requirements_Matrix_25-P-147JRD.xlsx XLSX spreadsheet
Show all 50

Jail Management System (JMS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U. S. Department of Justice

Federal Bureau of Investigation

Criminal Justice Information Services Division

Criminal Justice Information Services (CJIS) Security Policy

Version 6.0 12/27/2024

Prepared by:

FBI CJIS Information Security Officer

Approved by:

CJIS Advisory Policy Board i

CJISSECPOL v6.0

EXECUTIVE SUMMARY

Criminal and noncriminal justice agencies need timely and secure access to services that provide data wherever and whenever for stopping and reducing crime. In response to these needs, the Advisory Policy Board (APB) recommended to the Federal Bureau of Investigation (FBI) that the Criminal Justice Information Services (CJIS) Division authorize the expansion of the existing security management structure in 2019. Administered through a shared management philosophy, the CJIS Security Policy (CJISSECPOL) contains information security requirements, guidelines, and agreements reflecting the will of law enforcement and criminal justice agencies for protecting the systems that process, store, and transmit Criminal Justice Information (CJI). The Federal Information Security Management Act of 2014 provides further legal basis for the APB approved management, operational, and technical security requirements mandated to protect CJI and by extension the hardware, software and infrastructure required to enable the services provided to the criminal and noncriminal justice communities.

The essential premise of the CJISSECPOL is to provide appropriate controls to protect the full lifecycle of CJI, whether at rest or in transit. The CJISSECPOL provides guidance for the creation, viewing, modification, transmission, dissemination, storage, or destruction of CJI. This Policy applies to every individual—contractor, private entity, noncriminal justice agency representative, or member of a criminal justice entity—with access to, or who operate in support of, criminal and noncriminal justice services and information.

The CJISSECPOL integrates presidential directives, federal laws, FBI directives and the criminal and noncriminal justice community decisions along with guidance from the National Crime Prevention and Privacy Compact Council (Compact Council). The Policy is presented at both strategic and tactical levels and is periodically updated to reflect the security requirements of evolving technology and business models. The Policy features modular sections enabling more frequent updates to address emerging threats and new security measures. The provided security criteria assists agencies with designing and implementing systems to meet a minimum level of risk and security protection while enabling agencies the latitude to institute more stringent security requirements and controls based on their business model and local needs.

The CJISSECPOL strengthens the partnership between the FBI and CJIS Systems Agencies (CSA), including, in those states with separate authorities, the State Identification Bureaus (SIB), and Interface Agencies (IA). Further, as use of criminal history record information (CHRI) for noncriminal justice purposes continues to expand, the CJISSECPOL becomes increasingly important in guiding the National Crime Prevention and Privacy Compact Council and State Compact Officers in the secure exchange of CHRI.

The Policy describes the vision and captures the security concepts that set the policies, protections, roles, and responsibilities with minimal impact from changes in technology. The Policy empowers CSAs, SIBs, and IAs with the insight and ability to tune their security programs according to their risks, needs, budgets, and resource constraints while remaining compliant with the baseline level of security set forth in this Policy. The CJISSECPOL provides a security framework based on laws, standards, and elements of published and vetted policies for accomplishing the mission across the broad spectrum of the criminal justice and noncriminal justice communities.

ii

CHANGE MANAGEMENT

Revision Change Description Created/Changed by Date Approved By

6.0 Policy Modernization

Completion

Security Policy Modernization Task Force 12/27/2024 APB & Compact

Council iii

SUMMARY OF CHANGES

Version 6.0 APB Approved Changes

1. Modernizing the Executive Summary, Section 1: Introduction, Section 2:

CJISSECPOL Approach, and Section 3: Roles and Responsibilities in the CJISSECPOL, Spring 2024, APB#11, SA#2: update sections with approved changes.

2. Changing and Refreshing Authenticators in the CJISSECPOL, Spring 2024, APB#11, SA#3: clarifies which authenticator type requires annual changing and clarifies the use of a “banned password” list.

3. Modernizing System and Services Acquisition (SA) in the CJISSECPOL, Spring 2024, APB#11, SA#5: add definitions and modernize the CJIS Security Policy requirements for:

System and Services Acquisition Policy and Procedures Allocation of Resources System Development Lifecycle Acquisition Process System Documentation Security and Privacy Engineering Principles External System Services Developer Configuration Management Developer Testing and Evaluation Developer Process, Standards, and Tools

4. Modernizing Supply Chain and Risk Management (SR) in the CJISSECPOL, Spring

2024, APB#11, SA#6: modernize the CJIS Security Policy requirements for

Supply Chain Risk Management Policy and Procedures Supply Chain Risk Management Plan Acquisition Strategies, Tools, and Methods Notification Agreements Inspection of Systems or Components Component Disposal

5. Modernizing Personnel Security (PS) in the CJISSECPOL, Spring 2024, APB#11, SA#7: modernize the CJIS Security Policy requirements for

Personnel Security Policy and Procedures Position Risk Designation Personnel Screening Personnel Termination Personnel Transfer Access Agreements External Personnel Security iv

Personnel Sanctions Position Descriptions

6. Modernizing Assessment, Authorization, and Monitoring (CA) in the CJISSECPOL, Spring 2024, APB#11, SA#8: modernize the CJIS Security Policy requirements for

Assessment, Authorization, and Monitoring Policy and Procedures Control Assessments Information Exchange Plan of Action and Milestones Authorization Continuous Monitoring Internal System Connections

7. Remove Appendix J and K from the CJISSECPOL, Spring 2024, APB#11, SA#9:

remove the indicated appendices.

Administrative Changes 0F0F0F

1. There are no Administrative Changes in this version.

Note: Administrative changes are vetted through the Security and Access Subcommittee and not the entire APB process.

KEY TO APB APPROVED CHANGES (e.g., “Section 5.13 Mobile Devices, Fall 2013, APB#11, SA#6, Future CSP for Mobile Devices: add language”):

Section Number and Name Fall 2013 – Advisory Policy Board cycle and year APB# – Advisory Policy Board Topic number SA# – Security and Access Subcommittee Topic number Topic Paper Title Summary of change v

TABLE OF CONTENTS

Executive Summary ....................................................................................................................... i Change Management .................................................................................................................... ii Summary of Changes ................................................................................................................... iii Table of Contents ...........................................................................................................................v List of Figures ...............................................................................................................................xv List of Priorities.......................................................................................................................... xvi 1 Introduction

1.1 Purpose

1.2 Scope

1.3 Relationship to Local Security Policy and Other Policies

1.4 Terminology Used in This Document

1.5 Distribution of the CJIS Security Policy

2 CJIS Security Policy Approach

2.1 CJIS Security Policy Vision Statement

2.2 Architecture Independent

2.3 Risk Versus Realism

3 Roles and Responsibilities

3.1 Shared Management Philosophy

3.2 Roles and Responsibilities for Agencies and Parties

3.2.1 CJIS Systems Agencies (CSA)

3.2.2 CJIS Systems Officer (CSO)

3.2.3 Terminal Agency Coordinator (TAC)

3.2.4 Criminal Justice Agency (CJA)

3.2.5 Noncriminal Justice Agency (NCJA)

3.2.6 Contracting Agency (CA)

3.2.7 Agency Coordinator (AC)

3.2.8 CJIS Systems Agency Information Security Officer (CSA ISO)

3.2.9 Organizational Personnel with Security Responsibilities

3.2.10 FBI CJIS Division Information Security Officer (FBI CJIS ISO)

3.2.11 Repository Manager

3.2.12 IA Official

3.2.13 State Compact Officer (SCO)

4 Criminal Justice Information and Personally Identifiable Information

4.1 Criminal Justice Information (CJI)

4.1.1 Criminal History Record Information (CHRI)

4.2 Access, Use and Dissemination of Criminal History Record Information (CHRI), NCIC

Restricted Files Information, and NCIC Non-Restricted Files Information

4.2.1 Proper Access, Use, and Dissemination of CHRI

4.2.2 Proper Access, Use, and Dissemination of NCIC Restricted Files Information

4.2.3 Proper Access, Use, and Dissemination of NCIC Non-Restricted Files Information

4.2.3.1 For Official Purposes

4.2.3.2 For Other Authorized Purposes

4.2.3.3 CSO Authority in Other Circumstances

vi

4.2.4 Storage

4.2.5 Justification and Penalties

4.2.5.1 Justification

4.2.5.2 Penalties

4.3 Personally Identifiable Information (PII)

5 Policy and Implementation

5.1 Policy Area 1: Information Exchange Agreements

5.1.1 Information Exchange

5.1.2 Monitoring, Review, and Delivery of Services

5.1.2.1 Managing Changes to Service Providers

ACCESS CONTROL (AC)

AC-1 Policy and Procedures AC-2 Account Management

(1) Account Management | Automated System Account Management

(2) Account Management | Automated Temporary and Emergency Account Management

(3) Account Management | Disable Accounts

(4) Account Management | Automated Audit Actions

(5) Account Management | Inactivity Logout 28

(13) Account Management | Disable Accounts for High-Risk Individuals

AC-3 Access Enforcement

(14) Access Enforcement | Individual Access

AC-4 Information Flow Enforcement AC-5 Separation of Duties AC-6 Least Privilege

(1) Least Privilege | Authorize Access to Security Functions

(2) Least Privilege | Non-Privileged Access for Nonsecurity Functions

(5) Least Privilege | Privileged Accounts

(7) Least Privilege | Review of User Privileges

(9) Least Privilege | Log Use of Privileged Functions

(10) Least Privilege | Prohibit Non-Privileged Users from Executing Privileged Functions

AC-7 Unsuccessful Logon Attempts AC-8 System Use Notification AC-11 Device Lock

(1) Device Lock | Pattern-Hiding Displays AC-12 Session Termination AC-14 Permitted Actions without Identification or Authentication AC-17 Remote Access

(1) Remote Access | Monitoring and Control

(2) Remote Access | Protection of Confidentiality and Integrity Using Encryption

(3) Remote Access | Managed Access Control Points

(4) Remote Access | Privileged Commands and Access

AC-18 Wireless Access

(1) Wireless Access | Authentication and Encryption

(3) Wireless Access | Disable Wireless Networking vii

AC-19 Access Control for Mobile Devices

(5) Access Control for Mobile Devices | Full Device or Container-Based Encryption

AC-20 Use of External Systems

(1) Use of External Systems | Limits On Authorized Use

(2) Use of External Systems | Portable Storage Devices — Restricted Use

AC-21 Information Sharing AC-22 Publicly Accessible Content

AWARENESS AND TRAINING (AT)

AT-1 Policy and Procedures AT-2 Literacy Training and Awareness

(2) Literacy Training and Awareness | Insider Threat

(3) Literacy Training and Awareness | Social Engineering and Mining

AT-3 Role-Based Training

(5) Role-Based Training | Processing Personally Identifiable Information

AT-4 Training Records

AUDIT AND ACCOUNTABILITY (AU)

AU-1 Policy and Procedures AU-2 Event Logging AU-3 Content of Audit Records

(1) Content of Audit Records | Additional Audit Information

(3) Content of Audit Records | Limit Personally Identifiable Information Elements

AU-4 Audit Log Storage Capacity AU-5 Response to Audit Logging Process Failures AU-6 Audit Record Review, Analysis, and Reporting

(1) Audit Record Review, Analysis, and Reporting | Automated Process Integration

(3) Audit Record Review, Analysis, and Reporting | Correlate Audit Record Repositories

AU-7 Audit Record Reduction and Report Generation

(1) Audit Record Reduction and Report Generation | Automatic Processing AU-8 Time Stamps AU-9 Protection of Audit Information

(4) Protection of Audit Information | Access by Subset of Privileged Users AU-11 Audit Record Retention AU-12 Audit Record Generation

ASSESSMENT, AUTHORIZATION, AND MONITORING (CA)

CA-1 Policy and Procedures CA-2 Control Assessments

(1) Control Assessments | Independent Assessors CA-3 Information Exchange CA-5 Plan of Action and Milestones CA-6 Authorization CA-7 Continuous Monitoring

(1) Continuous Monitoring | Independent Assessment

(4) Continuous Monitoring | Risk Monitoring

CA-9 Internal System Connections

CONFIGURATION MANAGEMENT (CM)

viii

CM-1 Policy and Procedures CM-2 Baseline Configuration

(2) Baseline Configuration | Automation Support for Accuracy and Currency

(3) Baseline Configuration | Retention of Previous Configurations

(7) Baseline Configuration | Configure Systems and Components for High-Risk Areas ..68

CM-3 Configuration Change Control

(2) Configuration Change Control | Testing, Validation, and Documentation of Changes

(4) Configuration Change Control | Security and Privacy Representatives

CM-4 Impact Analyses

(2) Impact Analyses | Verification of Controls

CM-5 Access Restrictions for Change CM-6 Configuration Settings CM-7 Least Functionality

(1) Least Functionality | Periodic Review

(2) Least Functionality | Prevent Program Execution

(5) Least Functionality | Authorized Software — Allow-by-Exception

CM-8 System Component Inventory

(1) System Component Inventory | Updates During Installation and Removal

(3) System Component Inventory | Automated Unauthorized Component Detection

CM-9 Configuration Management Plan CM-10 Software Usage Restrictions CM-11 User-Installed Software CM-12 Information Location

(1) Information Location | Automated Tools to Support Information Location

CONTINGENCY PLANNING (CP)

CP-1 Policy and Procedures CP-2 Contingency Plan

(1) Contingency Plan | Coordinate with Related Plans

(3) Contingency Plan | Resume Mission and Business Functions

(8) Contingency Plan | Identify Critical Assets

CP-3 Contingency Training CP-4 Contingency Plan Testing

(1) Contingency Plan Testing | Coordinate with Related Plans CP-6 Alternate Storage Site

(1) Alternate Storage Site | Separation from Primary Site

(3) Alternate Storage Site | Accessibility

CP-7 Alternate Processing Site

(1) Alternate Processing Site | Separation from Primary Site

(2) Alternate Processing Site | Accessibility

(3) Alternate Processing Site | Priority of Service

CP-8 Telecommunications Services

(1) Telecommunications Services | Priority of Service Provisions

(2) Telecommunications Services | Single Points of Failure

CP-9 System Backup

(1) System Backup | Testing for Reliability and Integrity ix

(8) System Backup | Cryptographic Protection CP-10 System Recovery and Reconstitution

(2) System Recovery and Reconstitution | Transaction Recovery

IDENTIFICATION AND AUTHENTICATION (IA)

IA-0 Use of Originating Agency Identifiers in Transactions and Information Exchanges ...92 IA-1 Policy and Procedures IA-2 Identification and Authentication (Organizational Users)

(1) Identification and Authentication (Organizational Users) | Multi-Factor Authentication to Privileged Accounts

(2) Identification and Authentication (Organizational Users) | Multi-Factor Authentication to Non-Privileged Accounts

(8) Identification and Authentication (Organizational Users) | Access to Accounts — Replay Resistant

(12) Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials

IA-3 Device Identification and Authentication IA-4 Identifier Management

(4) Identifier Management | Identify User Status IA-5 Authenticator Management

(1) Authenticator Management | Authenticator Types

(a) Memorized Secret Authenticators and Verifiers:

(b) Look-Up Secret Authenticators and Verifiers

(c) Out-of-Band Authenticators and Verifiers

(d) OTP Authenticators and Verifiers

(e) Cryptographic Authenticators and Verifiers (Including Single- and Multi-Factor Cryptographic Authenticators, Both Hardware- and Software-Based)

(2) Authenticator Management | Public Key Based Authentication

(6) Authenticator Management | Protection of Authenticators

IA-6 Authentication Feedback IA-7 Cryptographic Module Authenticationf IA-8 Identification and Authentication (Non-Organizational Users)

(1) Identification and Authentication (Non-Organizational Users) | Acceptance of PIV Credentials from Other Agencies

(2) Identification and Authentication (Non-Organizational Users) | Acceptance of External Authenticators

(4) Identification and Authentication (Non-Organizational Users) | Use of Defined Profiles

IA-11 Re-Authentication IA-12 Identity Proofing

(2) Identity Proofing | Identity Evidence

(3) Identity Proofing | Identity Evidence Validation and Verification

(5) Identity Proofing | Address Confirmation

INCIDENT RESPONSE (IR)

IR-1 Policy and Procedures IR-2 Incident Response Training

(3) Incident Response Training | Breach x

IR-3 Incident Response Testing

(2) Incident Response Testing | Coordination with Related Plans

IR-4 Incident Handling

(1) Incident Handling | Automated Incident Handling Processes

IR-5 Incident Monitoring IR-6 Incident Reporting

(1) Incident Reporting | Automated Reporting

(3) Incident Reporting | Supply Chain Coordination

IR-7 Incident Response Assistance

(1) Incident Response Assistance | Automation Support for Availability of Information and Support 10f IR-8 Incident Response Plan

(1) Incident Response Plan | Breaches

MAINTENANCE (MA)

MA-1 Policy and Procedures MA-2 Controlled Maintenance MA-3 Maintenance Tools

(1) Maintenance Tools | Inspect Tools

(2) Maintenance Tools | Inspect Media

(3) Maintenance Tools | Prevent Unauthorized Removal

MA-4 Nonlocal Maintenance MA-5 Maintenance Personnel MA-6 Timely Maintenance

MEDIA PROTECTION (MP)

MP-1 Policy and Procedures MP-2 Media Access MP-3 Media Marking MP-4 Media Storage MP-5 Media Transport MP-6 Media Sanitization MP-7 Media Use

PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

PE-1 Policy and Procedures PE-2 Physical Access Authorizations PE-3 Physical Access Control PE-4 Access Control for Transmission PE-5 Access Control for Output Devices PE-6 Monitoring Physical Access

(1) Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment PE-8 Visitor Access Records

(3) Visitor Access Records | Limit Personally Identifiable Information Elements PE-9 Power Equipment and Cabling PE-10 Emergency Shutoff PE-11 Emergency Power PE-12 Emergency Lighting PE-13 Fire Protection xi

(1) Fire Protection | Detection Systems — Automatic Activation and Notification PE-14 Environmental Controls PE-15 Water Damage Protection PE-16 Delivery and Removal PE-17 Alternate Work Site

PLANNING (PL)

PL-1 Policy and Procedures PL-2 System Security and Privacy Plans PL-4 Rules of Behavior

(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions

PL-8 Security and Privacy Architectures PL-9 Central Management PL-10 Baseline Selection PL-11 Baseline Tailoring

PERSONNEL SECURITY (PS)

PS-1 Policy and Procedures PS-2 Position Risk Designation PS-3 Personnel Screening PS-4 Personnel Termination PS-5 Personnel Transfer PS-6 Access Agreements PS-7 External Personnel Security PS-8 Personnel Sanctions PS-9 Position Descriptions

RISK ASSESSMENT (RA)

RA-1 Policy and Procedures RA-2 Security Categorization RA-3 Risk Assessment RA-5 Vulnerability Monitoring and Scanning

(2) Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be Scanned

(5) Vulnerability Monitoring and Scanning | Privileged Access

(11) Vulnerability Monitoring and Scanning | Public Disclosure Program

RA-7 Risk Response RA-9 Criticality Analysis

SYSTEM AND SERVICES ACQUISITION (SA)

SA-1 Policy and Procedures SA-2 Allocation of Resources SA-3 System Development Life Cycle SA-4 Acquisition Process

(1) Acquisition Process | Functional Properties of Controls

(2) Acquisition Process | Design and Implementation Information for Controls

(9) Acquisition Process | Functions, Ports, Protocols, and Services In Use

(10) Acquisition Process | Use of Approved Piv Products

SA-5 System Documentation SA-8 Security and Privacy Engineering Principles xii

(33) Security and Privacy Engineering Principles | Minimization SA-9 External System Services

(2) External System Services | Identification of Functions, Ports, Protocols, and Services

SA-10 Developer Configuration Management SA-11 Developer Testing and Evaluation SA-15 Development Process, Standards, and Tools

(1) Development Process, Standards, and Tools |Criticality Analysis SA-22 Unsupported System Components

SYSTEMS AND COMMUNICATIONS PROTECTION (SC)

SC-1 Policy and Procedures SC-2 Separation of System and User Functionality SC-4 Information in Shared System Resources SC-5 Denial-of-Service Protection SC-7 Boundary Protection

(3) Boundary Protection | Access Points

(4) Boundary Protection | External Telecommunications Services

(5) Boundary Protection | Deny by Default — Allow by Exception

(7) Boundary Protection | Split Tunneling for Remote Devices

(8) Boundary Protection | Route Traffic to Authenticated Proxy Servers

(24) Boundary Protection | Personally Identifiable Information

SC-8 Transmission Confidentiality and Integrity

(1) Transmission Confidentiality and Integrity | Cryptographic Protection

SC-10 Network Disconnect SC-12 Cryptographic Key Establishment and Management SC-13 Cryptographic Protection SC-15 Collaborative Computing Devices and Applications SC-17 Public Key Infrastructure Certificates SC-18 Mobile Code SC-20 Secure Name/Address Resolution Service (Authoritative Source) SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) SC-22 Architecture and Provisioning for Name/Address Resolution Service SC-23 Session Authenticity SC-28 Protection of Information at Rest

(1) Protection of Information at Rest | Cryptographic Protection SC-39 Process Isolation

SYSTEM AND INFORMATION INTEGRITY (SI)

SI-1 Policy and Procedures SI-2 Flaw Remediation

(2) Flaw Remediation | Automated Flaw Remediation Status SI-3 Malicious Code Protection SI-4 System Monitoring

(2) System Monitoring | Automated Tools and Mechanisms for Real-Time Analysis

(4) System Monitoring | Inbound and Outbound Communications Traffic

(5) System Monitoring | System-Generated Alerts

SI-5 Security Alerts, Advisories, and Directives xiii

SI-7 Software, Firmware, and Information Integrity

(1) Software, Firmware, and Information Integrity | Integrity Checks

(7) Software, Firmware, and Information Integrity | Integration of Detection and Response

SI-8 Spam Protection

(2) Spam Protection | Automatic Updates SI-10 Information Input Validation SI-11 Error Handling SI-12 Information Management and Retention

(1) Information Management and Retention | Limit Personally Identifiable Information Elements

(2) Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training, and Research

(3) Information Management and Retention | Information Disposal SI-16 Memory Protection

SUPPLY CHAIN RISK MANAGEMENT (SR)

SR-1 Policy and Procedures SR-2 Supply Chain Risk Management Plan

(1) Supply Chain Risk Management Plan | Establish SCRM Team SR-5 Acquisition Strategies, Tools, and Methods SR-8 Notification Agreements SR-10 Inspection of Systems or Components SR-12 Component Disposal

5.20 Policy Area 20: Mobile Devices

5.20.1 Wireless Communications Technologies

5.20.1.1 802.11 Wireless Protocols

5.20.1.2 Cellular Devices

5.20.1.2.1 Cellular Service Abroad

5.20.1.2.2 Voice Transmissions Over Cellular Devices

5.20.1.3 Bluetooth

5.20.1.4 Mobile Hotspots

5.20.2 Mobile Device Management (MDM)

5.20.3 Wireless Device Risk Mitigations

5.20.4 System Integrity

5.20.4.1 Patching/Updates

5.20.4.2 Malicious Code Protection

5.20.4.3 Personal Firewall

5.20.5 Incident Response

5.20.6 Access Control

5.20.7 Identification and Authentication

5.20.7.1 Local Device Authentication

5.20.7.2 Advanced Authentication

5.20.7.2.1 Compensating Controls

5.20.7.3 Device Certificates

Appendices APPENDIX A: TERMS AND DEFINITIONS ...................................................................... A-1 xiv

APPENDIX B: ACRONYMS .................................................................................................B-1 APPENDIX C: NETWORK TOPOLOGY DIAGRAMS .......................................................C-1

APPENDIX D: SAMPLE INFORMATION EXCHANGE AGREEMENTS ....................... D-1

D.1 CJIS User Agreement ................................................................................................ D.1-1 D.2 Management Control Agreement .............................................................................. D.2-1 D.3 Noncriminal Justice Agency Agreement & Memorandum of Understanding .......... D.3-1 D.4 Interagency Connection Agreement .......................................................................... D.4-1

APPENDIX E: SECURITY FORUMS AND ORGANIZATIONAL ENTITIES .................. E-1

APPENDIX F: SAMPLE FORMS .......................................................................................... F-1

F.1 Security Incident Response form ................................................................................ F.1-1 APPENDIX G: BEST PRACTICES ...................................................................................... G-1

G.1 Virtualization ............................................................................................................ G.1-1 G.2 Voice over Internet Protocol ..................................................................................... G.2-1 G.3 Cloud Computing ...................................................................................................... G.3-1 G.4 Mobile Appendix ...................................................................................................... G.4-1 G.5 Administrator Accounts for Least Privilege and Separation of Duties ..................... G.5-1 G.6 Encryption ................................................................................................................. G.6-1 G.7 Incident Response ..................................................................................................... G.7-1 G.8 Secure Coding ........................................................................................................... G.8-1

APPENDIX H: SECURITY ADDENDUM ........................................................................... H-1 APPENDIX I: REFERENCES ................................................................................................. I-1 xv

LIST OF FIGURES

Figure 1 – Overview Diagram of Strategic Functions and Policy Components Figure 2 – Dissemination of restricted and non-restricted NCIC data Figure 3 – Information Exchange Agreements Implemented by a Local Police Department Figure 4 – Security Awareness Training Use Cases Figure 5 – A Local Police Department’s Configuration Management Controls Figure 6 – Digital Identity Model Figure 7 – Notional Strengths of Evidence Types Figure 8 – Types of Identity Evidence Security Features Figure 9 – Validating Identity Evidence Figure 10 – Verification Methods and Strengths Figure 11 – Incident Response Process Initiated by an Incident in a Local Police Department .174 Figure 12 – A Local Police Department’s Media Management Policies Figure 13 – Personnel Security Use Cases Figure 14 – System and Communications Protection and Information Integrity Use Cases xvi

LIST OF PRIORITIES

NOTE: An asterisk (‘*’) in the Priority column indicates an existing control from version 5.9.

No. Control Name Enhancements Priority

AC-1 POLICY AND PROCEDURES AC-1 P2

AC-2 ACCOUNT MANAGEMENT AC-2 (1) (2) (3) (4) (5) (13) P1

AC-3 ACCESS ENFORCEMENT AC-3 (14) P1*

AC-4 INFORMATION FLOW ENFORCEMENT AC-4 P1*

AC-5 SEPARATION OF DUTIES AC-5 P1*

AC-6 LEAST PRIVILEGE AC-6 (1) (2) (5) (7) (9) (10) P1*

AC-7 UNSUCCESSFUL LOGON ATTEMPTS AC-7 P3*

AC-8 SYSTEM USE NOTIFICATION AC-8 P2*

AC-11 DEVICE LOCK AC-11 (1) P4*

AC-12 SESSION TERMINATION AC-12 P3

AC-14 PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION AC-14 P4

AC-17 REMOTE ACCESS AC-17 (1) (2) (3) (4) P1

AC-18 WIRELESS ACCESS AC-18 (1) (3) P2*

AC-19 ACCESS CONTROL FOR MOBILE DEVICES AC-19 (5) P2*

AC-20 USE OF EXTERNAL SYSTEMS AC-20 (1) (2) P1

AC-21 INFORMATION SHARING AC-21 P3*

AC-22 PUBLICLY ACCESSIBLE CONTENT AC-22 P4

AT-1 POLICY AND PROCEDURES AT-1 P2

AT-2 LITERACY TRAINING AND AWARENESS AT-2 (2) (3) P2*

AT-3 ROLE-BASED TRAINING AT-3 P2*

AT-3 ROLE-BASED TRAINING | PROCESSING PERSONALLY IDENTIFIABLE INFORMATION AT-3 (5) P2

AT-4 TRAINING RECORDS AT-4 P4*

AU-1 POLICY AND PROCEDURES AU-1 P2

AU-2 EVENT LOGGING AU-2 P2*

AU-3 CONTENT OF AUDIT RECORDS AU-3 (1) P2*

AU-3 CONTENT OF AUDIT RECORDS | LIMIT PERSONALLY IDENTIFIABLE INFORMATION

ELEMENTS AU-3 (3) P2

AU-4 AUDIT LOG STORAGE CAPACITY AU-4 P2

AU-5 RESPONSE TO AUDIT LOGGING PROCESS FAILURES AU-5 P2*

AU-6 AUDIT RECORD REVIEW, ANALYSIS, AND REPORTING AU-6 (1) (3) P2*

AU-7 AUDIT RECORD REDUCTION AND REPORT GENERATION AU-7 (1) P3

AU-8 TIME STAMPS AU-8 P2*

AU-9 PROTECTION OF AUDIT INFORMATION AU-9 (4) P2*

AU-11 AUDIT RECORD RETENTION AU-11 P4*

AU-12 AUDIT RECORD GENERATION AU-12 P2

CA-1 POLICY AND PROCEDURES CA-1 P2

CA-2 CONTROL ASSESSMENTS CA-2 (1) P3

CA-3 INFORMATION EXCHANGE CA-3 P2*

CA-5 PLAN OF ACTION AND MILESTONES CA-5 P4

xvii

No. Control Name Enhancements Priority

CA-6 AUTHORIZATION CA-6 P3

CA-7 CONTINUOUS MONITORING CA-7 (1) (4) P1

CA-9 INTERNAL SYSTEM CONNECTIONS CA-9 P3

CM-1 POLICY AND PROCEDURES CM-1 P2

CM-2 BASELINE CONFIGURATION CM-2 (2) (3) (7) P1

CM-3 CONFIGURATION CHANGE CONTROL CM-3 (2) (4) P2

CM-4 IMPACT ANALYSES CM-4 (2) P3

CM-5 ACCESS RESTRICTIONS FOR CHANGE CM-5 P1

CM-6 CONFIGURATION SETTINGS CM-6 P1

CM-7 LEAST FUNCTIONALITY CM-7 (1) (2) (5) P1

CM-8 SYSTEM COMPONENT INVENTORY CM-8 (1) (3) P1

CM-9 CONFIGURATION MANAGEMENT PLAN CM-9 P2

CM-10 SOFTWARE USAGE RESTRICTIONS CM-10 P3

CM-11 USER-INSTALLED SOFTWARE CM-11 P2

CM-12 INFORMATION LOCATION CM-12 (1) P2

CP-1 POLICY AND PROCEDURES CP-1 P2

CP-2 CONTINGENCY PLAN CP-2 (1) (3) (8) P2

CP-3 CONTINGENCY TRAINING CP-3 P3

CP-4 CONTINGENCY PLAN TESTING CP-4 (1) P3

CP-6 ALTERNATE STORAGE SITE CP-6 (1) (3) P2

CP-7 ALTERNATE PROCESSING SITE CP-7 (1) (2) (3) P2

CP-8 TELECOMMUNICATIONS SERVICES CP-8 (1) (2) P2

CP-9 SYSTEM BACKUP CP-9 (1) (8) P2

CP-10 SYSTEM RECOVERY AND RECONSTITUTION CP-10 (2) P2

IA-1 POLICY AND PROCEDURES IA-1 P2

IA-2 IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS) IA-2 (1) (2) (8) (12) P1

IA-3 DEVICE IDENTIFICATION AND AUTHENTICATION IA-3 P2

IA-4 IDENTIFIER MANAGEMENT IA-4 (4) P2*

IA-5 AUTHENTICATOR MANAGEMENT IA-5 (1) (2) (6) P1

IA-6 AUTHENTICATION FEEDBACK IA-6 P3*

IA-7 CRYPTOGRAPHIC MODULE AUTHENTICATION IA-7 P2

IA-8 IDENTIFICATION AND AUTHENTICATION (NON-ORGANIZATIONAL USERS) IA-8 (1) (2) (4) P2

IA-11 RE-AUTHENTICATION IA-11 P2

IA-12 IDENTITY PROOFING IA-12 (2) (3) (5) P2

IR-1 POLICY AND PROCEDURES IR-1 P2*

IR-2 INCIDENT RESPONSE TRAINING IR-2 P3*

IR-2 INCIDENT RESPONSE TRAINING | BREACH IR-2 (3) P3

IR-3 INCIDENT RESPONSE TESTING IR-3 (2) P3

IR-4 INCIDENT HANDLING IR-4 (1) P2*

IR-5 INCIDENT MONITORING IR-5 P2*

IR-6 INCIDENT REPORTING IR-6 (1) (3) P2*

IR-7 INCIDENT RESPONSE ASSISTANCE IR-7 (1) P3*

xviii

IR-8 INCIDENT RESPONSE PLAN IR-8 P2*

IR-8 INCIDENT RESPONSE PLAN | BREACHES IR-8 (1) P2

MA-1 POLICY AND PROCEDURES MA-1 P2

MA-2 CONTROLLED MAINTENANCE MA-2 P3

MA-3 MAINTENANCE TOOLS MA-3 (1) (2) (3) P4

MA-4 NONLOCAL MAINTENANCE MA-4 P3

MA-5 MAINTENANCE PERSONNEL MA-5 P3

MA-6 TIMELY MAINTENANCE MA-6 P3

MP-1 POLICY AND PROCEDURES MP-1 P2*

MP-2 MEDIA ACCESS MP-2 P2*

MP-3 MEDIA MARKING MP-3 P3*

MP-4 MEDIA STORAGE MP-4 P2*

MP-5 MEDIA TRANSPORT MP-5 P2*

MP-6 MEDIA SANITIZATION MP-6 P2*

MP-7 MEDIA USE MP-7 P2*

PE-1 POLICY AND PROCEDURES PE-1 P2

PE-2 PHYSICAL ACCESS AUTHORIZATIONS PE-2 P2*

PE-3 PHYSICAL ACCESS CONTROL PE-3 P2*

PE-4 ACCESS CONTROL FOR TRANSMISSION PE-4 P2*

PE-5 ACCESS CONTROL FOR OUTPUT DEVICES PE-5 P3*

PE-6 MONITORING PHYSICAL ACCESS PE-6 (1) P2*

PE-8 VISITOR ACCESS RECORDS PE-8 (3) P4

PE-9 POWER EQUIPMENT AND CABLING PE-9 P2

PE-10 EMERGENCY SHUTOFF PE-10 P2

PE-11 EMERGENCY POWER PE-11 P2

PE-12 EMERGENCY LIGHTING PE-12 P2

PE-13 FIRE PROTECTION PE-13 (1) P2

PE-14 ENVIRONMENTAL CONTROLS PE-14 P2

PE-15 WATER DAMAGE PROTECTION PE-15 P2

PE-16 DELIVERY AND REMOVAL PE-16 P3

PE-17 ALTERNATE WORK SITE PE-17 P3*

PL-1 POLICY AND PROCEDURES PL-1 P2

PL-2 SYSTEM SECURITY AND PRIVACY PLANS PL-2 P2

PL-4 RULES OF BEHAVIOR PL-4 (1) P3

PL-8 SECURITY AND PRIVACY ARCHITECTURES PL-8 P2

PL-9 CENTRAL MANAGEMENT PL-9 P4

PL-10 BASELINE SELECTION PL-10 P3

PL-11 BASELINE TAILORING PL-11 P3

PS-1 POLICY AND PROCEDURES PS-1 P2

PS-2 POSITION RISK DESIGNATION PS-2 P2

PS-3 PERSONNEL SCREENING PS-3 P2*

PS-4 PERSONNEL TERMINATION PS-4 P2

xix

PS-5 PERSONNEL TRANSFER PS-5 P3*

PS-6 ACCESS AGREEMENTS PS-6 P4

PS-7 EXTERNAL PERSONNEL SECURITY PS-7 P2*

PS-8 PERSONNEL SANCTIONS PS-8 P4

PS-9 POSITION DESCRIPTIONS PS-9 P4

RA-1 POLICY AND PROCEDURES RA-1 P2

RA-2 SECURITY CATEGORIZATION RA-2 P2

RA-3 RISK ASSESSMENT RA-3 (1) P2

RA-5 VULNERABILITY MONITORING AND SCANNING RA-5 (2) (5) (11) P1

RA-7 RISK RESPONSE RA-7 P2

RA-9 CRITICALITY ANALYSIS RA-9 P2

SA-1 POLICY AND PROCEDURES SA-1 P2

SA-2 ALLOCATION OF RESOURCES SA-2 P2

SA-3 SYSTEM DEVELOPMENT LIFE CYCLE SA-3 P2

SA-4 ACQUISITION PROCESS SA-4 (1) (2) (9) (10) P2

SA-5 SYSTEM DOCUMENTATION SA-5 P3

SA-8 SECURITY AND PRIVACY ENGINEERING PRINCIPLES SA-8 (33) P2

SA-9 EXTERNAL SYSTEM SERVICES SA-9 (2) P2

SA-10 DEVELOPER CONFIGURATION MANAGEMENT SA-10 P2

SA-11 DEVELOPER TESTING AND EVALUATION SA-11 P2

SA-15 DEVELOPMENT PROCESS, STANDARDS, AND TOOLS SA-15 (3) P3

SA-22 UNSUPPORTED SYSTEM COMPONENTS SA-22 P2

SC-1 POLICY AND PROCEDURES SC-1 P2

SC-2 SEPARATION OF SYSTEM AND USER FUNCTIONALITY SC-2 P2*

SC-4 INFORMATION IN SHARED SYSTEM RESOURCES SC-4 P2*

SC-5 DENIAL-OF-SERVICE PROTECTION SC-5 P2

SC-7 BOUNDARY PROTECTION SC-7 (3) (4) (5) (7) (8) (24) P1

SC-8 TRANSMISSION CONFIDENTIALITY AND INTEGRITY SC-8 (1) P2*

SC-10 NETWORK DISCONNECT SC-10 P3

SC-12 CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT SC-12 P2*

SC-13 CRYPTOGRAPHIC PROTECTION SC-13 P2*

SC-15 COLLABORATIVE COMPUTING DEVICES AND APPLICATIONS SC-15 P2

SC-17 PUBLIC KEY INFRASTRUCTURE CERTIFICATES SC-17 P2*

SC-18 MOBILE CODE SC-18 P3

SC-20 SECURE NAME/ADDRESS RESOLUTION SERVICE (AUTHORITATIVE SOURCE) SC-20 P2

SC-21 SECURE NAME/ADDRESS RESOLUTION SERVICE (RECURSIVE OR CACHING RESOLVER) SC-21 P2

SC-22 ARCHITECTURE AND PROVISIONING FOR NAME/ADDRESS RESOLUTION SERVICE SC-22 P2

SC-23 SESSION AUTHENTICITY SC-23 P2

SC-28 PROTECTION OF INFORMATION AT REST SC-28 (1) P2*

SC-39 PROCESS ISOLATION SC-39 P2*

SI-1 POLICY AND PROCEDURES SI-1 P2

SI-2 FLAW REMEDIATION SI-2 (2) P1

xx

SI-3 MALICIOUS CODE PROTECTION SI-3 P1

SI-4 SYSTEM MONITORING SI-4 (2) (4) (5) P1

SI-5 SECURITY ALERTS, ADVISORIES, AND DIRECTIVES SI-5 P2*

SI-7 SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY SI-7 (1) (7) P1

SI-8 SPAM PROTECTION SI-8 (2) P3*

SI-10 INFORMATION INPUT VALIDATION SI-10 P1

SI-11 ERROR HANDLING SI-11 P3

SI-12 INFORMATION MANAGEMENT AND RETENTION SI-12 (1) (2) (3) P3

SI-16 MEMORY PROTECTION SI-16 P2

SI-18 PERSONALLY IDENTIFIABLE INFORMATION QUALITY OPERATIONS SI-18 (4) P4

SI-19 DE-IDENTIFICATION SI-19 P4

SR-1 POLICY AND PROCEDURES SR-1 P2

SR-2 SUPPLY CHAIN RISK MANAGEMENT PLAN SR-2 (1) P3

SR-3 SUPPLY CHAIN CONTROLS AND PROCESSES SR-3 P3

SR-5 ACQUISITION STRATEGIES, TOOLS, AND METHODS SR-5 P2

SR-6 SUPPLIER ASSESSMENTS AND REVIEWS SR-6 P2

SR-8 NOTIFICATION AGREEMENTS SR-8 P3

SR-10 INSPECTION OF SYSTEMS OR COMPONENTS SR-10 P3

SR-11 COMPONENT AUTHENTICITY SR-11 (1) (2) P2

SR-12 COMPONENT DISPOSAL SR-12 P3

1 INTRODUCTION

This section details the purpose of this document, its scope, relationship to other information security policies, and its distribution constraints.

1.1 Purpose

The CJISSECPOL provides Criminal Justice Agencies (CJA), Noncriminal Justice Agencies (NCJA), and Interface Agencies (IA) with a minimum set of security requirements for access to Federal Bureau of Investigation (FBI) Criminal Justice Information Services (CJIS) Division systems and information and to protect and safeguard Criminal Justice Information (CJI). The essential premise of the CJISSECPOL is to provide the appropriate controls to ensure the continuity of the protection of CJI, from creation through dissemination or destruction, whether at rest or in transit.

1.2 Scope

At the consent of the advisory process, and taking into consideration federal law and state statutes, the CJISSECPOL applies to all entities with access to, or that operate systems which are used to process, store, or transmit CJI. The CJISSECPOL provides minimum security requirements associated with the creation, viewing, modification, transmission, dissemination, storage, or destruction of CJI.

Entities engaged in the interstate exchange of CHRI for noncriminal justice purposes are also governed by the standards and rules promulgated by the Compact Council.

1.3 Relationship to Local Security Policy and Other Policies

The CJISSECPOL may be used as the sole security policy for the agency. The local agency may complement the CJISSECPOL with a local policy, or the agency may develop their own stand-alone security policy; however, the CJISSECPOL shall always be the minimum standard. State, local, Tribal, territorial (SLTT), and Federal agencies may augment or implement more stringent policies or requirements.

The agency shall develop, disseminate, and maintain formal, documented policy and procedures to facilitate the implementation of the CJISSECPOL and, where applicable, the local security policy. The policies and procedures shall be consistent with applicable laws, executive orders, directives, policies, regulations, standards, and guidance. Procedures developed for CJISSECPOL areas can be developed for the security program in general, and for a particular information system, when required.

1.4 Terminology Used in This Document

Effective in version 5.9.5, priority and implementation markings have been added to the modernized controls. Based on the FBI Director approved APB recommendation, beginning October 1, 2024, requirements existing prior to the CJISSECPOL modernization (i.e., version 5.9) and those identified as Priority 1 ([Priority 1]) will be the set of sanctionable requirements.

• Non-modernized sections do not have markings but are considered “existing” requirements and continue to be auditable and sanctionable.

• “Existing” modernized requirements and indicated by the [Existing] marking.

• Priority 1 modernized requirements are indicated by the [Priority 1] marking.

• All [Priority 2], [Priority 3], and [Priority 4] modernized requirements fall into a zero-cycle status. The zero-cycle begins October 1, 2024 and ends September 30, 2027.

The following terms are used interchangeably throughout this document:

• Agency and Organization: The two terms in this document refer to any entity that submits or receives information, by any means, to/from FBI CJIS systems or services.

• Organizational Personnel: Individuals belonging to an agency or organization (see above) or contracted to an agency or organization to provide services under contract.

• Information and Data: Both terms refer to CJI.

• System, Information System, Service, or named applications like NCIC: all refer to connections to the FBI’s criminal justice information repositories and the equipment used to establish said connections.

• Requirement and Control: These terms refer to a condition or capability that must be met or possessed by a system or system element to satisfy an agreement, standard, specification, or other formally imposed document.

Appendix A and B provide extensive lists of the terms and acronyms.

Appendix I contains all of the references used in this Policy and may contain additional sources that could apply to any section.

1.5 Distribution of the CJIS Security Policy

The CJISSECPOL, version 6.0 and later, is a publicly available document and may be posted and shared without restrictions.

2 CJIS SECURITY POLICY APPROACH

The CJISSECPOL represents the shared responsibility among FBI CJIS, CJIS Systems Agency (CSA), State Identification Bureaus (SIB), and Interface Agency (IA) for the appropriate protection of CJI.

2.1 CJIS Security Policy Vision Statement

The executive summary of this document describes the vision in terms of business needs for confidentiality, integrity, and availability of information. The APB collaborates with the FBI CJIS Division to ensure that the Policy remains updated to meet evolving business, technology and security needs.

2.2 Architecture Independent

The CJISSECPOL looks at the data (information), services, and protection controls that apply regardless of the implementation architecture. Architectural independence is not intended to lessen the importance of systems, but provide for the replacement of one technology with another while ensuring the controls required to protect the information remain constant. This objective and conceptual focus on security policy areas provide the guidance and standards while avoiding the impact of the constantly changing landscape of technical innovations. The architectural independence of the Policy provides agencies with the flexibility for tuning their information security infrastructure and policies to reflect their own environments.

2.3 Risk Versus Realism

Each agency faces risk unique to that agency. It is quite possible that several agencies could encounter the same type of risk however depending on resources would mitigate that risk differently. In that light, a risk-based approach can be used when implementing requirements.

3 ROLES AND RESPONSIBILITIES

3.1 Shared Management Philosophy

In the scope of information security, the FBI CJIS Division employs a shared management philosophy with SLTT and Federal criminal justice agencies. Although an advisory policy board for the NCIC has existed since 1969, the Director of the FBI established the CJIS APB in March 1994 to enable appropriate input and recommend policy with respect to CJIS services. Through the APB and its Subcommittees and Working Groups, consideration is given to the needs of the criminal justice and law enforcement community regarding public policy, statutory and privacy aspects, as well as national security relative to CJIS systems and information. The APB, including a representative of the Compact Council, represents criminal and noncriminal justice agencies throughout the United States, its territories, and Canada.

The FBI has a similar relationship with the Compact Council, which governs the interstate exchange of criminal history records for noncriminal justice purposes. The Compact Council is mandated by federal law to promulgate rules and procedures for the use of the Interstate Identification Index (III) for noncriminal justice purposes. To meet that responsibility, the Compact Council depends on the CJISSECPOL as the definitive source for standards defining the security and privacy of records exchanged with noncriminal justice practitioners.

3.2 Roles and Responsibilities for Agencies and Parties

It is the responsibility of all agencies covered under this Policy to ensure the protection of CJI between the FBI CJIS Division and its user community. The following figure provides an abstract representation of the strategic functions and roles such as governance and operations.

Figure 1 – Overview Diagram of Strategic Functions and Policy Components

This section provides a description of the following entities and roles:

1. CJIS Systems Agency (CSA).

2. CJIS Systems Officer (CSO).

3. Terminal Agency Coordinator (TAC).

4. Criminal Justice Agency (CJA).

5. Noncriminal Justice Agency (NCJA).

6. Contracting Agency (CA).

7. Agency Coordinator (AC).

8. CJIS Systems Agency (CSA) Information Security Officer (ISO).

9. Organizational Personnel with Security Responsibilities.

10. FBI CJIS Division Information Security Officer (ISO).

11. SIB Chief/Repository Manager/Chief Administrator.

12. Interface Agency (IA) Official

13. State Compact Officer (SCO).

3.2.1 CJIS Systems Agencies (CSA)

The CSA is responsible for establishing and administering an information technology security program throughout the CSA’s user community, to include the local levels. The head of each CSA shall appoint a CJIS Systems Officer (CSO). The CSA may impose more stringent or additional protection measures than outlined in this document. Such decisions shall be documented and kept current.

3.2.2 CJIS Systems Officer (CSO)

The CSO is an individual located within the CSA responsible for the administration of the CJIS network for the CSA. Pursuant to the Bylaws for the CJIS Advisory Policy Board and Working Groups, the role of CSO shall not be outsourced. The CSO may delegate responsibilities to subordinate agencies. The CSO shall set, maintain, and enforce the following:

1. Standards for the selection, supervision, and separation of personnel who have access to

CJI.

2. Policy governing the operation of computers, access devices, circuits, hubs, routers, firewalls, and other components that comprise and support a telecommunications network and related CJIS systems used to process, store, or transmit CJI, guaranteeing the priority of service required by the law enforcement community, confidentiality, integrity, and availability of CJI.

a. Ensure appropriate use, enforce system discipline, and ensure CJIS Division operating procedures are followed by all users of the respective services and information.

b. Ensure state/federal agency compliance with policies approved by the APB and adopted by the FBI.

c. Ensure the appointment of the CSA ISO and determine the extent of authority to the

CSA ISO.

d. Ensure the designation of a Terminal Agency Coordinator (TAC) within each agency with devices accessing CJIS systems.

e. Ensure each agency having access to CJI has someone designated as the Organizational Personnel with Security Responsibilities.

f. Ensure each Organizational Personnel with Security Responsibilities receives enhanced security awareness training (ref. Awareness and Training (AT)).

g. Approve access to FBI CJIS systems.

h. Assume ultimate responsibility for managing the security of CJIS systems within their state and/or agency.

i. Perform other related duties outlined by the user agreements with the FBI CJIS

Division.

3. External System Services of Criminal Justice Functions Responsibility for the management and control of security requirements for information systems which process, store, or transmit CJI shall remain with the CJA. Management and control includes the authority to:

a. Set and enforce standards for the selection, supervision, and termination of access to

CJI;

b. Set and enforce policy governing the operation of computers, circuits, and telecommunications terminals,

c. Guarantee the priority service as determined by the CSA.

3.2.3 Terminal Agency Coordinator (TAC)

The TAC serves as the point-of-contact at the local agency for matters relating to CJIS information access. The TAC administers CJIS systems programs within the local agency and oversees the agency’s compliance with CJIS systems policies.

3.2.4 Criminal Justice Agency (CJA)

A CJA is defined as a court, a governmental agency, or any subunit of a governmental agency which performs the administration of criminal justice pursuant to a statute or executive order and which allocates a substantial part of its annual budget to the administration of criminal justice.

State and federal Inspectors General Offices are included.

3.2.5 Noncriminal Justice Agency (NCJA)

A NCJA is defined (for the purposes of access to CJI) as an entity or any subunit thereof that provides services primarily for purposes other than the administration of criminal justice.

3.2.6 Contracting Agency (CA)

A CA is an agency, whether a CJA, NCJA (public), or NCJA (private), that enters into an agreement with a private contractor subject to the CJIS Security Addendum, The Security and Management Control Outsourcing Standard for Non-Channelers, of the Security and Management Control Outsourcing Standard for Channeling. The CA entering into an agreement with a contractor shall appoint an Agency Coordinator.

3.2.7 Agency Coordinator (AC)

An AC is a staff member of the CGA who manages the agreement between the Contractor and agency. The AC shall be responsible for the supervision and integrity of the system, training and continuing education of employees and operators, scheduling of initial training and testing, and certification testing and all required reports by NCIC. The AC shall:

1. Understand the communications, records capabilities, and needs of the Contractor which is accessing federal and state records through or because of its relationship with the CGA.

2. Participate in related meetings and provide input and comments for system improvement.

3. Receive information from the CGA (e.g., system updates) and disseminate it to appropriate

Contractor employees.

4. Maintain and update manuals applicable to the effectuation of the agreement, and provide them to the Contractor.

5. Maintain up-to-date records of Contractor’s employees who access the system, including name, date of birth, social security number, date fingerprint card(s) submitted, date security clearance issued, and date initially trained, tested, certified or recertified (if applicable).

6. Train or ensure the training of Contractor personnel. If Contractor personnel access NCIC, schedule the operators for testing or a certification exam with the CSA staff, or AC staff with permission from the CSA staff as consistent with the NCIC policy.

7. The AC will not permit an untrained/untested or non-certified Contractor employee to access CJI or systems supporting CJI where access to CJI can be gained.

8. Where appropriate, ensure compliance by the Contractor with NCIC validation requirements.

9. Provide completed applicant fingerprint cards on each Contractor employee who accesses the system to the CGA (or, where appropriate, CSA) for criminal background investigation prior to such employee accessing the system.

10. Any other responsibility…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .