FBI CJIS Security Policy
Governance and Agreements

FBI CJIS Security Policy CJIS-2: Security Awareness Training

Conduct regular personnel training on CJI risks, handling and incident reporting

What else in your programme already covers this

This control maps to 37 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • ASD37-37 Personnel management (Very Good)

FDA 21 CFR Part 11 · 1 control

  • Part11.10 Controls for closed systems (21 CFR §11.10)

ISO 13485 · 1 control

ISO 27799 · 1 control

ISO/IEC 27011:2024 · 1 control

MARS-E · 1 control

  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • 3.2.1 Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following: • Coverage for all locations of stored account data.

NIST SP 800-66 · 1 control

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • DSOMM-1 Culture, Organization, Education, and Governance
  • OMANCS-8 Third-Party + Supply Chain Risk, Awareness Training, Physical Security, Compliance Audit
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Governance and Agreements

Query this from an agent

The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.