CJIS Security Awareness Training Cheat Sheet | CybeReady (2024)

Who’s the last organization you’d expect to be a cyberattack victim? If you answered law enforcement, you’d be correct—but the problem is, it’s happening right now. Police and law enforcement agencies are under cyber assault, and these developments put sensitive information, ongoing investigations, and the very fabric of justice at grave risk.

A recent study has highlighted several ongoing dangers to law enforcement agencies, including email hacks and cybercriminals using social engineering techniques to issue false subpoenas and Emergency Data Requests to big tech companies like Apple and Meta, to gather detailed information on their targets illegally. This is even more concerning because a Motorola Solutions survey found that only 30% of law enforcement respondents have a plan ready for cyber incidents or use threat intelligence—and just 54% undertake cybersecurity training initiatives.

The escalating threat landscape underscores the vital role of CJIS (Criminal Justice Information Services) security awareness training—a program specifically crafted to guide individuals involved with CJIS in safeguarding critical information. This program encompasses various facets of security, including compliance, data protection, and incident response.

This post will be your “cheat sheet” for everything you need to know about CJIS security compliance, and the CJIS security awareness training your law enforcement organization needs to be prepared for.

What is CJIS security compliance?

CJIS security compliance embodies standards and regulations that direct law enforcement agencies within the United States to secure and preserve Criminal Justice Information (CJI). This information, which contains sensitive data concerning criminal activities, investigations, and individuals, necessitates stringent protection to maintain the confidentiality and effectiveness of law enforcement operations.

The CJIS Security Policy is a robust framework stipulating the minimal security prerequisites and controls to shield Criminal Justice Information (CJI). This dynamic policy encompasses directives issued by the president and the FBI, federal statutes, and decisions rendered by the Advisory Policy Board in the criminal justice community. Additionally, it integrates insights from the National Institute of Standards and Technology (NIST), reflecting evolving security stipulations over time.

CJIS Security Awareness Training Cheat Sheet | CybeReady (1)

An essential aspect of this policy is detailing thirteen critical areas that private entities, including cloud service providers, must scrutinize to ensure their cloud services align with CJIS standards. This evaluation process is closely aligned with the guidelines in NIST 800-53, forming the foundation of the Federal Risk and Authorization Management Program (FedRAMP).

To further fortify the security measures, all private contractors involved in CJI processing must comply with the CJIS Security Addendum. This uniform agreement, endorsed by the US Attorney General, guarantees the security and privacy of CJI, as necessitated by the Security Policy. It binds the contractor to uphold a security regimen that complies with federal and state laws, regulations, and standards while restricting the utilization of CJI to the objectives outlined by the providing government agency.

What are the 4 levels of CJIS security compliance?

To cater to different law enforcement agencies’ unique needs, CJIS security compliance is stratified into four distinct levels, each having specific requirements. These levels are formulated to accommodate varying data types and corresponding security necessities.

Level 1: Basic Security Awareness

Primarily intended for individuals needing rudimentary security training, focusing on the significance of security measures and adherence to CJIS policies.

Level 2: Security Awareness Training

Tailored for those with physical access to CJI, instructing on data access and handling protocols.

Level 3: Additional Security Training

Designed for authorized personnel who can alter or manage CJI, emphasizing responsibilities and security protocols.

Level 4: Advanced Security Training

Geared towards IT personnel and administrators responsible for overseeing the technical infrastructure supporting CJI systems, with education on system security, data integrity protection, and incident response.

Thorough training at all levels not only protects CJI data but also builds an organizational cybersecurity awareness culture.

CJIS Security Awareness Training Cheat Sheet | CybeReady (2)

Who is subject to CJIS security compliance?

Compliance with CJIS security standards is mandatory for everyone interacting with CJI. This encompasses:

  • Law enforcement personnel (CJAs)
  • Vendors
  • Contractors
  • Non-criminal justice agencies (NCJAs)

The frequency and duration of CJIS security awareness training may vary based on the compliance level assigned to an agency or individual. They can be influenced by factors such as training format, materials used, and session pacing. Consequently, organizations should customize their training programs to meet their specific needs.

What’s the difference between CJAs and NCJAs?

Criminal justice agencies (CJAs) are directly connected to the criminal justice system. They are responsible for upholding the law.

Examples of CJAs:

  • Police Department.
  • Sheriff’s Office.
  • Federal Bureau of Investigation (FBI).
  • State Department of Corrections.
  • District Attorney’s Office.

Non-criminal justice agencies (NCJAs) are not directly involved in law enforcement. But, they need to access CJIS data for specific tasks like background checks, licensing, and immigration.

Examples of NCJAs:

  • Department of Motor Vehicles (DMV).
  • Department of Health.
  • Public School District.
  • Human Resources Department.
  • Environmental Protection Agency (EPA).

CJIS Security Awareness Training Cheat Sheet | CybeReady (3)

What are the CJIS Security Awareness Training Requirements?

Specific requirements are stipulated for each compliance level to ensure that individuals and organizations with access to CJI receive appropriate training to safeguard this information.

Here are the CJIS security awareness training requirements for each level:

Policy AreaTitleDescription
1Information Exchange AgreementsEstablish formal collaborations between organizations or agencies exchanging CJI, affirming adherence to the requisite CJIS security protocols.
2Security Awareness TrainingObligatory basic CJIS security awareness training for all personnel handling CJI, to be completed within six months of their initial appointment. The CSP outlines the specificities of these four distinct training levels.
3Incident ResponseDevelopment and enactment of protocols to address incident responses, facilitating the identification, containment, alleviation, and recuperation from data infringements or assaults.
4Auditing and AccountabilityCreation of system audit logs for specified events, particularly scrutinizing all interactions with CJI. This involves tracking the individuals accessing the data, the timing, and the motives behind their access, under the oversight of administrators.
5Access ControlInstituting mechanisms to regulate and oversee user accessibility to data and network systems effectively.
6Identification and AuthenticationAdoption of stringent authentication practices, inclusive of multi-factor authentication, to safeguard sensitive information access.
7Configuration ManagementStructured management of alterations in software configurations, spanning software updates to hardware modifications, necessitating comprehensive documentation and safeguarding against unauthorized intrusions during transitions.
8Media ProtectionGuaranteeing the secure disposal or destruction of CJI documents and data once they have surpassed their utility period.
9Physical ProtectionMandating robust physical and personnel security measures at all CJIS facilities to shield CJI data, employing means such as surveillance cameras and alarm systems.
10System & Communications Protection & Information IntegrityDeployment of fortified network security infrastructure incorporating elements like firewalls, encryption, antivirus software, and intrusion prevention systems to thwart potential breaches.
11Formal AuditsPeriodic and formalized security evaluations for organizations handling CJI in any capacity, ensuring strict adherence to CJIS security protocols.
12Personnel SecurityImplementation of comprehensive security vetting processes for all staff, contractors, and vendors accessing CJI, encompassing fingerprint-based checks coordinated with IAFIS alongside residential state verifications.
13Mobile DevicesEnforcing a stringent usage policy for all mobile gadgets accessing CJI, potentially supplemented by additional security protocols paralleling the safeguards established for in-house devices.

It’s imperative to note that this is not a one-off requirement; regular training is essential to keep abreast of evolving threats and the latest best practices and to continuously improve organizational cyber resilience.

Getting certified in CJIS is an important career goal for personnel working with criminal justice information. It shows they meet the necessary security standards and can be trusted with sensitive data.

CJIS certification comes in four different compliance levels, as explained above, and you can get certified at any level based on your job role. However, there are two crucial steps to follow to become CJIS-certified:

1. Meeting Security Requirements

The first step involves following security policies and procedures outlined in the CJIS security policy. It includes understanding encryption principles, password management, and responding to security incidents.

2. Security Awareness Training

The second step is completing security awareness training specific to your CJIS compliance level. It covers various aspects, like access control, incident response, and recognizing and mitigating cyber threats.

CJIS Security Awareness Training Cheat Sheet | CybeReady (4)

CybeReady: The CJIS Security Awareness Training Solution

As law enforcement agencies become increasingly targeted by cybercriminals, protecting sensitive information and upholding the foundations of justice have never been more critical. In this context, CJIS security emerges as a vital shield against potential threats, necessitating regular training and certification to stay ahead of evolving cyber risks.

While CJIS compliance and certification requirements can seem complex, the required cybersecurity awareness training doesn’t have to be. CybeReady offers a comprehensive platform that makes security awareness training effective and manageable.

Featuring customized training modules, engaging and informative learning methods, progress monitoring, and a flexible training pace, CybeReady offers CJA, NCJA, contractor, and vendor organizations programs that ensure you are thoroughly prepared to tackle the challenges of CJIS compliance.

Connect with CybeReady today to learn how we can facilitate effective training for your team.

CJIS Security Awareness Training Cheat Sheet | CybeReady (2024)

FAQs

How many questions is the CJIS test? ›

You will have 1 hour to take the 25 question test. Take the test. To pass, you will need to achieve at least a 70 % (18 of 25 correct).

How do you prepare for security awareness training? ›

4 Tips to Develop Successful Security Awareness Training
  1. Create High-Quality Content. ...
  2. Choose Whether to Deploy Personalized or Pre-built Training Platforms. ...
  3. Decide Whether Training Content Should Be Risk- or Role-based. ...
  4. Invest in Real-world Phishing Simulations.
Oct 9, 2023

How often is CJIS security awareness training? ›

DOJ requires all agencies to provide basic security awareness training for all new employees and all appropriate personnel who have access to Criminal Justice Information within six months of initial assignment, and biennially thereafter, who have access to Criminal Justice Information.

What is CJIS security level 2? ›

Level 2: Security Awareness Training

Tailored for those with physical access to CJI, instructing on data access and handling protocols.

How many CJIS controls are there? ›

The CJIS Security Policy defines 13 areas that private contractors such as cloud service providers must evaluate to determine if their use of cloud services can be consistent with CJIS requirements.

What is CJIS level 4 certification? ›

Level 2: This training is for authorized individuals with access to physical CJI. Level 3: Authorized personnel with physical access who can modify CJI receive this level of training. Level 4: IT personnel like administrators receive this level of security awareness training.

What are the security requirements for CJIS? ›

CJIS — What It Is and How to Stay CJIS Compliant
  • A limit of 5 unsuccessful login attempts by a user accessing CJIS.
  • Event logging various login activities, including password changes.
  • Weekly audit reviews.
  • Active account management moderation.
  • Session lock after 30 minutes of inactivity.

What is CJIS online training? ›

CJIS is Criminal Justice Information Services. You need certain certifications to access certain law enforcement databases. and those certifications need to be renewed every 2 or so years.

Does security awareness expire? ›

More information about STCW Security Awareness. The STCW Security Awareness course takes half a day of your time in which you will learn how to be aware of danger on board. After successful completion of this course the participant will receive a STCW (A VI/6-1) certificate. This certificate is valid for life.

What does CJIS stand for? ›

The mission of the California Justice Information Services (CJIS) Division is to provide accurate, timely, and comprehensive criminal history and analysis data to its client agencies, which include California's local police and sheriff's departments, district attorneys, and local and state regulatory agencies.

Is CJIS a security clearance? ›

CJIS compliance is an important compliance standard for law enforcement at the local, state, and federal levels, and is designed to ensure data security in law enforcement. The Criminal Justice Information Services Division is the largest division of the Federal Bureau of Investigation.

What is the Triple I police code? ›

The Interstate Identification Index (III) is also, known as “Triple I” provides for the decentralized interstate III provides for the decentralized interstate exchange of Criminal History Record Information (CHRI) and functions as part of the FBI's CJIS Division's Integrated Automated Fingerprint Identification System ...

What are CJIS requirements? ›

A minimum of 128 bit encryption is required, and keys used to decrypt data must be adequately complex (at least 10 characters long, a mix of upper and lowercase letters, numbers and special characters) and changed as soon as authorized personnel no longer need access.

Is CJIS and NCIC the same? ›

It is the largest division in the FBI. Programs initially consolidated under the CJIS Division included the National Crime Information Center (NCIC), Uniform Crime Reporting (UCR), and Fingerprint Identification.

How often is CJIS audited? ›

CAU audits all CSAs and repositories every three years. Resources permitting, the unit may conduct special audits upon request. The unit also selects local agencies at random, taking into account an agency's past performance, along with how long and how frequently the agency has been using CJIS services.

What are the examples of CJIS data? ›

Examples include name, social security number, or other biometric records alone and or in conjunction with information such as DOB, place of birth, mother's maiden name, etc. This information must be extracted from CJI for official business only.

Top Articles
Pengertian Domain dan Fungsi Domain
Top 20 Most Visited Countries In The World 2022
Obituary for Mark E. Rimer at Hudson-Rimer Funeral Chapel
Otc School Calendar
Watch After Ever Happy 123Movies
Pizza Hut Order Online Near Me
Tyson Employee Paperless
Select Walgreens Stores: Lasko 16" Stand Fan $7.50 & More + Free Store Pickup on $10+
Trey Yingst Parents Nationality
Myhr North Memorial
9:00 A.m. Cdt
Uwa Schedule
What Is a Food Bowl and Why Are They So Popular?
Ta Travel Center Las Cruces Photos
Trinket Of Advanced Weaponry
Vector Driver Setup
Patriot Ledger Obits Today
Ice Quartz Osrs
Hdmovie 2
Charm City Kings 123Movies
M Life Insider
Www.dunkin Baskin Runs On You.com
Boys golf: Back-nine surge clinches Ottumwa Invite title for DC-G
Journal articles: 'Mark P. Herschede Trust' – Grafiati
Dishonored Subreddit
Watch My Best Friend's Exorcism Online Free
Sejinming Telegram
The Nearest Dollar Store To My Location
3850 Colonial Blvd Suite 100 Fort Myers Fl 33966
Aogf Causes.benevity
Account Now Login In
No Cable Schedule
O'reilly's Los Banos
Wgu Admissions Login
Alabama Adventure Coupons
Age Of Attila's Rain Crossword
Craigslist In Visalia California
Natalya's Vengeance Set Dungeon
Boostmaster Lin Yupoo
Degreeworks Sbu
Standard Schnauzer For Sale Craigslist
Bryant Air Conditioner Parts Diagram
2026 Rankings Update: Tyran Stokes cements No. 1 status, Brandon McCoy, NBA legacies lead loaded SoCal class
Plusword 358
Norville Breast Center At Alamance Regional
Math Nation Algebra 2 Practice Book Answer Key
Builders Best Do It Center
David Knowles, journalist who helped make the Telegraph podcast Ukraine: The Latest a runaway success
Rubrankings Austin
Morse Road Bmv Hours
Neuer Extraction-Shooter auf Steam will Escape from Tarkov Konkurrenz machen, wird von echten Militär-Veteranen entwickelt
O'reilly's Covington Tennessee
Latest Posts
Article information

Author: Frankie Dare

Last Updated:

Views: 6393

Rating: 4.2 / 5 (73 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Frankie Dare

Birthday: 2000-01-27

Address: Suite 313 45115 Caridad Freeway, Port Barabaraville, MS 66713

Phone: +3769542039359

Job: Sales Manager

Hobby: Baton twirling, Stand-up comedy, Leather crafting, Rugby, tabletop games, Jigsaw puzzles, Air sports

Introduction: My name is Frankie Dare, I am a funny, beautiful, proud, fair, pleasant, cheerful, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.