FBI CJIS Security Policy
The FBI Criminal Justice Information Services (CJIS) Security Policy establishes minimum security requirements for access to FBI CJIS Division systems and information including the National Crime Information Center (NCIC), Interstate Identification Index (III), and National Instant Criminal Background Check System (NICS). Version 5.9.4 (2024) applies to all entities accessing criminal justice information (CJI) including law enforcement, contractors, and cloud service providers.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
Access Control
| Code | Title |
|---|---|
| CJIS-5.5 | Access Control |
Access Control and Authentication
FedRAMP-specific access control and identification/authentication requirements
Account Management
| Code | Title |
|---|---|
| CJIS-AM-1 | Account Management |
Audit
| Code | Title |
|---|---|
| CJIS-5.4 | Auditing and Accountability |
Awareness and Training
| Code | Title |
|---|---|
| CJIS-5.2 | Security Awareness Training |
Compliance
| Code | Title |
|---|---|
| CJIS-5.11 | Formal Audits |
Configuration Management
| Code | Title |
|---|---|
| CJIS-5.7 | Configuration Management |
| CJIS-CM-1 | Cloud Service Provider Controls |
Governance and Agreements
| Code | Title |
|---|---|
| CJIS-1 | Information Exchange Agreements |
| CJIS-2 | Security Awareness Training |
| CJIS-3 | Personnel Security |
Identification and Authentication
| Code | Title |
|---|---|
| CJIS-5.6 | Identification and Authentication |
Incident Response
| Code | Title |
|---|---|
| CJIS-5.3 | Incident Response |
| CJIS-IR-2 | Notification to CJIS Systems Officer |
Information Exchange
| Code | Title |
|---|---|
| CJIS-5.1 | Information Exchange Agreements |
Media Protection
| Code | Title |
|---|---|
| CJIS-5.8 | Media Protection |
Mobile
| Code | Title |
|---|---|
| CJIS-5.13 | Mobile Devices |
Personnel
| Code | Title |
|---|---|
| CJIS-5.12 | Personnel Security |
Physical Security
| Code | Title |
|---|---|
| CJIS-5.9 | Physical Protection |
| CJIS-PE-2 | Physically Secure Location |
Physical and Environmental Security
| Code | Title |
|---|---|
| CJIS-14 | Physical Protection |
| CJIS-15 | Mobile Devices |
| CJIS-16 | Cloud Computing |
Risk and Supply Chain
| Code | Title |
|---|---|
| CJIS-17 | Risk Assessment |
| CJIS-18 | Security Assessment and Authorization |
| CJIS-19 | Supply Chain Risk Management |
| CJIS-20 | System Acquisition |
System Security
| Code | Title |
|---|---|
| CJIS-10 | System and Information Integrity |
| CJIS-7 | Configuration Management |
| CJIS-8 | Media Protection |
| CJIS-9 | System and Communications Protection |
System and Communications Protection
| Code | Title |
|---|---|
| CJIS-5.10 | System and Communications Protection |
| CJIS-SC-1 | Boundary Protection |
| CJIS-SC-2 | Wireless Network Protections |
Your Compliance Coverage
If you comply with FBI CJIS Security Policy, you already cover:
NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
24%
8 controls mapped
Compare →NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
24%
8 controls mapped
Compare →NIST Privacy Framework
21%
7 controls mapped
Compare →+ 259 more: AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (21%), NIST SP 800-53 Rev 5 (21%)
See all 262 mapped frameworks ↓Maps to 262 other frameworks
Frequently Asked Questions
What is FBI CJIS Security Policy?
FBI CJIS Security Policy is a compliance framework from United States (FBI) with 19 domains and 33 controls. The FBI Criminal Justice Information Services (CJIS) Security Policy establishes minimum security requirements for access to FBI CJIS Division systems and information including the National Crime Information Center (NCIC), Interstate Identification Index (III), and National Instant Criminal Background Check System (NICS). Version 5.9.4 (2024) applies to all entities accessing criminal justice information (CJI) including law enforcement, contractors, and cloud service providers. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does FBI CJIS Security Policy have?
FBI CJIS Security Policy has 33 controls organised across 19 domains. The largest domains are Risk and Supply Chain (4 controls), System Security (4 controls), Governance and Agreements (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does FBI CJIS Security Policy map to?
FBI CJIS Security Policy maps to 262 other compliance frameworks. The top mapping partners are NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (24% coverage), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (24% coverage), NIST Privacy Framework (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with FBI CJIS Security Policy compliance?
Start your FBI CJIS Security Policy compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FBI CJIS Security Policy requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required