CJIS Security Policy controls, proven on every scan.
CISGuard automates the technical CJIS Security Policy areas that audits hinge on: access control, auditing and accountability, and configuration management, with air-gapped deployment for criminal justice networks.
CJIS at a glance, for fast retrieval.
Atomic factual claims auditors and search engines can cite verbatim.
- Governing body
- FBI CJIS Division, with state CJIS Systems Agencies (CSAs)
- Protected data
- Criminal Justice Information (CJI): criminal history, biometrics, case data
- Who must comply
- Law enforcement, courts, corrections, and their vendors and cloud providers
- Control alignment
- Requirements aligned with NIST 800-53; CISGuard maps 50 controls
- Enforcement
- Periodic audits by the FBI and state CJIS Systems Agencies
- Air-gapped support
- Yes; suits isolated criminal justice and dispatch networks
What is CJIS?
The FBI CJIS Security Policy governs the protection of Criminal Justice Information (CJI): criminal histories, fingerprints, case data, and related records. It binds every entity that accesses CJI, including police departments, sheriffs, courts, corrections, dispatch centers, and the private vendors and cloud providers that serve them. The policy defines requirement areas spanning access control, identification and authentication, auditing and accountability, configuration management, and system and communications protection, and its recent revisions align the requirements with NIST 800-53 controls. Compliance is enforced through the CJIS Systems Agency in each state and periodic FBI audits. Because most CJIS technical requirements are configuration requirements on the systems that touch CJI, CISGuard's continuous CIS benchmark scanning evidences them directly, on networks that are frequently isolated by design.
CJIS Security Policy areas CISGuard automates.
Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.
- Access Control
- Controls
- Least privilege, session lock, unsuccessful login limits
- Mapped by
- CIS Account + Privilege Management benchmarks
- Identification and Authentication
- Controls
- Password standards, MFA for CJI access
- Mapped by
- CIS Password Policy + MFA configuration benchmarks
- Auditing and Accountability
- Controls
- Auditable events, log content, log protection
- Mapped by
- CIS Audit Policy benchmarks (Windows + Linux)
- Configuration Management
- Controls
- Least functionality, baseline configurations, change control
- Mapped by
- Continuous CIS scanning + drift detection
- System and Communications Protection
- Controls
- Encryption in transit, boundary protection
- Mapped by
- CIS Cryptography + Network benchmarks
- Formal Audits
- Controls
- Evidence production for FBI / CSA audit cycles
- Mapped by
- Framework Coverage Report + immutable audit trail
How CISGuard automates CJIS evidence.
CJIS audits examine whether the systems that store, process, or transmit CJI are configured to policy: password and MFA settings, audit logging, least functionality, encryption, and documented change control. Agencies and vendors usually reconstruct this evidence manually before each audit cycle. CISGuard makes it a standing record instead: continuous CIS benchmark scans across every in-scope Windows and Linux system show per-control pass/fail against hardening baselines aligned with the NIST 800-53 controls CJIS requirements map to; drift detection documents that configurations stayed compliant between scans; the immutable audit trail evidences the auditing and accountability area. Because many criminal justice networks are segmented or fully isolated, CISGuard's on-premises and air-gapped deployment matters: full scanning, reporting, and evidence generation with zero internet dependency. CISGuard is not an auditor and does not grant CJIS compliance; it produces the technical evidence your CSA and FBI audits examine.
Evidence artifacts CISGuard generates.
Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.
- Per-asset CIS benchmark results for every system in the CJI environment
- Configuration management evidence: baselines, drift events, change history
- Audit-policy verification evidence for auditing and accountability requirements
- Password, session, and MFA configuration status across in-scope systems
- Framework Coverage Report mapped through NIST 800-53 for audit preparation
- Air-gapped deployment evidence for isolated criminal justice networks
CJIS questions, answered directly.
Who has to comply with the CJIS Security Policy?
Every entity that accesses Criminal Justice Information: police departments, sheriffs' offices, courts, corrections, prosecutors, dispatch centers, and, critically, the private vendors, IT contractors, and cloud providers that handle CJI on their behalf. Vendor personnel and systems fall under the same requirements as agency systems, typically formalized through agreements with the agency and the state CJIS Systems Agency.
Does CISGuard make my agency CJIS compliant?
No single tool makes you CJIS compliant, and CISGuard is not an auditor or certifying body. CJIS compliance spans policy, personnel screening, physical security, and training as well as technical controls. What CISGuard automates is the technical-control evidence: continuous proof that in-scope systems meet hardening, access control, auditing, and configuration management requirements, which is the portion of the audit that consumes the most preparation time.
How does CISGuard map to CJIS requirements?
Recent CJIS Security Policy revisions align the requirements with NIST 800-53 controls, and CISGuard already tags each of its 3,928 CIS benchmark controls with 800-53 control IDs. Scan results therefore roll up to the control families behind CJIS areas such as access control, identification and authentication, auditing and accountability, and configuration management. The Framework Coverage Report presents that rollup with drill-down to per-asset scan evidence.
Can CISGuard run on an isolated or air-gapped criminal justice network?
Yes. CISGuard deploys fully on-premises and supports air-gapped operation: installation from secure media, local scanning, local reporting, and zero external dependency. This fits CJI environments where internet-connected SaaS scanners are unacceptable or simply unreachable, including segmented dispatch networks and isolated records systems. Updates to benchmark content are applied through the same offline media process.
How does CISGuard help with FBI and CSA audit cycles?
Audits are periodic, but the policy expects controls to operate continuously between them. CISGuard's scheduled scans every 4-24 hours build a timestamped history showing each system's compliance posture across the entire audit interval, not just audit week. When the FBI or your CJIS Systems Agency arrives, the Framework Coverage Report and drift history are already assembled, replacing weeks of screenshot collection.
Continue exploring CISGuard coverage.
NIST 800-53
CISGuard automates 50 NIST 800-53 Rev. 5 controls across 20 control families directly from CIS benchmark scans, the foundation for FedRAMP, FISMA, CMMC, and federal compliance programs.
Read more →FISMA
CISGuard maps 50 NIST 800-53 controls across the baselines FISMA systems inherit, automating the configuration evidence behind ATO packages and the continuous monitoring FISMA reporting demands.
Read more →StateRAMP
CISGuard maps 50 NIST 800-53 controls underpinning StateRAMP security requirements, giving cloud providers serving state and local government continuous configuration evidence for snapshots, authorization, and ongoing monitoring.
Read more →Ready for CJIS readiness?
Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.