Frameworks
CJIS Security Policy (US Criminal Justice)
The FBI's security policy for criminal justice data — strict, specific, and non-negotiable for gov-tech.
Book a demoThe FBI's Criminal Justice Information Services Security Policy governs any system that stores, processes, or transmits criminal justice information — including the growing ecosystem of cloud and SaaS vendors serving law enforcement and courts. Its requirements are prescriptive, down to advanced authentication and personnel screening.
What makes CJIS distinctive
Beyond standard controls, CJIS mandates specifics: fingerprint-based background checks for personnel with access, security awareness training on defined cycles, advanced authentication for CJI access, detailed audit logging, and encryption meeting FIPS 140 standards. Agreements (like the CJIS Security Addendum) bind vendors contractually to the policy.
How Compriska helps
Compriska tracks CJIS policy areas as owned, evidenced controls — personnel screening records, training cycles, access and audit configurations — and cross-maps the substantial overlap with NIST 800-53, so gov-tech vendors run one program for both.
Frequently asked questions
Is there a CJIS certification?
No formal certification exists — compliance is assessed by state CJIS Systems Agencies and through audits. Vendors demonstrate alignment with documentation and signed agreements, which is exactly the evidence discipline a GRC platform maintains.
Other frameworks
Automate CJIS with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo