Skip to main content
Image coming soon

FBI CJIS Security Policy Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
FBI CJIS Security Policy · Criminal Justice Information · Evidence & Implementation Kit
Pass your CJIS audit, without mapping thirteen policy areas to evidence yourself.
Every CJIS policy area, from advanced authentication and FIPS-validated encryption through personnel screening and the triennial audit, handed to you as an adopt-ready control with the evidence a CJIS auditor examines.
Audit-ready in a weekend, not a quarter.

Here is the honest situation. Any agency or vendor that touches Criminal Justice Information is bound by the FBI CJIS Security Policy and audited against it every three years. It runs across thirteen policy areas, and the ones that catch people are specific: advanced multi-factor authentication from outside a secure location, FIPS 140 validated encryption in transit and at rest, fingerprint-based background checks before unescorted access, and the CSA and Terminal Agency Coordinator governance. Mapping all thirteen areas to controls and audit evidence is weeks of work, and one gap fails the audit.

This Kit removes that mapping. It is every CJIS policy area written as an adopt-ready control you personalize in a weekend, with the evidence a CJIS auditor examines.

What you get, the moment you buy

34
Policy areas as adopt-ready controls. Every CJIS area, from information exchange agreements and training through access control, encryption, personnel security and mobile devices, written so you personalize and apply it. The advanced-authentication and FIPS rules are built in.
34
Audit-evidence checklists. For each control, exactly what a CJIS auditor examines, plus where agencies fail the audit, so you close it before the triennial review.
1
CJIS Control Matrix, pre-built. Every control in a working spreadsheet, ready to record in-place status and evidence location.
1
Gap & Readiness Assessment. Score each control and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the FBI CJIS Security Policy across its thirteen policy areas, with advanced authentication, FIPS 140 validated encryption and fingerprint-based screening called out. Editable Word and Excel files.

The triennial audit is not optional
CJIS agencies are audited by the FBI every three years, and vendors by their CSA. The evidence this Kit tells you to assemble, from authentication logs to sanitization records to background-check documentation, is exactly what that audit examines, area by area.

What one control looks like

This is the advanced authentication requirement, the area that catches the most agencies. All 34 are built to this depth.

5.6.2 Advanced authentication and multi-factor AUTHENTICATION
Meet this requirement

[Agency] shall implement advanced authentication, meaning multi-factor authentication combining something the user knows with something the user has or is, for access to CJI that originates from outside a physically secure location, and shall apply the same requirement to remote and mobile access so that a compromised password alone cannot yield access to Criminal Justice Information.

Compliance note.

Advanced authentication is the signature CJIS control; the trigger is access from outside a physically secure location, not merely remote work.

Evidence a CJIS auditor examines
  • Multi-factor authentication configuration for remote and mobile CJI access
  • List of access paths classified by whether they originate inside a secure location
  • Enrollment records for tokens, authenticator apps, or biometric factors
  • Test results demonstrating access is denied without the second factor
Common finding they raise: Officers query CJI from patrol laptops with only a username and password because advanced authentication was never deployed for field access.

Why this is not another template pack

  • The evidence is the point. A policy you cannot evidence fails the audit. This tells you exactly what a CJIS auditor examines and where agencies fail, for every area.
  • The hard requirements built in. Advanced authentication, FIPS 140 validated encryption and fingerprint-based screening are written into the controls, the requirements agencies most often miss.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. CJIS increasingly maps onto NIST 800-53, so this work feeds a broader security program if you run one.

Who buys this

Law enforcement and criminal justice agencies, and the vendors and cloud providers that handle Criminal Justice Information, plus the security leads and Terminal Agency Coordinators who own compliance. Whether it is a first audit or a renewal, you save weeks and walk in with the controls and evidence ready.

By the end of the weekend you will have
✓  An adopt-ready control for all 34 areas
✓  A completed CJIS control matrix
✓  The evidence a CJIS auditor examines
✓  Your authentication and encryption requirements met
✓  A readiness percentage and a fix list
✓  The common audit failures closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Does it cover advanced authentication? Yes. The multi-factor requirement for access from outside a physically secure location is its own control, because it is the most common audit failure.

Does it cover vendors and cloud? Yes. The information-exchange-agreement and personnel-security controls cover contractors, the Security Addendum and background screening.

Which version does it track? The current CJIS Security Policy structure across the thirteen policy areas. Verify precise sub-clause numbers against your CSA's version in force.

What if it is not for me? A 30-day money-back guarantee.

Do not map thirteen policy areas by hand.
Every CJIS area is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be audit-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com