Frameworks · Americas
CJIS Security Policy
The FBI's Criminal Justice Information Services (CJIS) Security Policy sets the minimum security requirements for agencies and their vendors that access criminal justice information. Version 6.0, dated 27 December 2024, completed the move of the policy onto NIST SP 800-53 Rev. 5 control families. Later point releases add annual changes, and xmodo records the edition an agency is assessed against.
Who it applies to
It applies to law enforcement and criminal justice agencies. It also applies to the cloud providers, software vendors and contractors that store, process or transmit criminal justice information for them.
Main requirements
Access & identity
Personnel screening, identification, advanced authentication and access control apply to CJI.
Protection
CJI is encrypted in transit and at rest, with media protection and physical security in place.
Operations
This area covers audit and accountability, configuration management, incident response and security awareness.
Agreements
Security addenda and agreements are in place with vendors and non-criminal-justice partners.
How xmodo supports it
- 1
The policy follows its NIST SP 800-53 Rev. 5 family structure, so a provider with a FedRAMP or 800-53 programme gets credit for that work immediately.
- 2
The assessed edition is stored as a structured field and checked against the FBI's current publication, because point releases arrive every year.
- 3
Vendor agreements and personnel screening evidence are managed in the third-party and personnel modules.
Related frameworks
CJIS Security Policy shares requirements with the frameworks below. Controls you already run for any of them count towards CJIS Security Policy as well.
Frequently asked questions
Which version are agencies assessed against?
Agencies are assessed against the edition named in the CJIS audit baseline, which lags behind the newest point release. xmodo records the assessed edition and shows the differences from the newest publication.