$ techbeacon▋
CVE & Exploits

FBI Updates CJIS Security Policy, Raising Encryption and Scan Standards for Law‑Enforcement IT

FBI Updates CJIS Security Policy, Raising Encryption and Scan Standards for Law‑Enforcement IT

The Federal Bureau of Investigation released version 6.1 of its Criminal Justice Information Services (CJIS) Security Policy, introducing tighter rules on data encryption, vulnerability scanning and continuous security monitoring. The revisions aim to close gaps that have emerged as agencies adopt cloud services and remote‑work tools, ensuring that sensitive criminal‑justice information remains protected against increasingly sophisticated cyber threats.

Among the most notable changes is a requirement for agencies to employ end‑to‑end encryption for data both at rest and in transit, expanding on the prior baseline that focused mainly on storage. The policy also mandates more frequent vulnerability assessments, pushing organizations to run automated scans on a weekly basis rather than the previous quarterly cadence. These steps reflect a broader shift toward a “continuous assessment” model, where security posture is evaluated in near real‑time rather than through periodic audits.

Identity and access management (IAM) provisions have been sharpened as well. The new version clarifies password complexity expectations, urging the use of longer passphrases and disallowing reuse across systems. Multi‑factor authentication (MFA) is now compulsory for all remote access to CJIS‑covered networks, and agencies must document the specific MFA methods employed, whether token‑based, biometrics, or mobile push notifications. The policy also calls for regular review of privileged accounts, with a focus on minimizing the number of users holding elevated rights.

Compliance officers and IT security teams are expected to update their policies and procedures to align with v6.1 within a twelve‑month window. Guidance from the FBI’s CJIS Security Office suggests a phased approach: first, inventory all systems handling CJIS data; second, verify that encryption protocols meet the new standards; third, implement automated scanning tools; and finally, audit authentication mechanisms for MFA and password hygiene. Agencies that fail to meet the deadlines could face penalties, including loss of access to the national CJIS network.

The rollout arrives at a time when law‑enforcement agencies are grappling with budget constraints and a shortage of cybersecurity talent. Experts note that while the heightened requirements may strain resources, they also provide a clearer framework for risk mitigation. By mandating continuous monitoring and stronger identity controls, the FBI hopes to reduce the likelihood of data breaches that could compromise investigations or endanger public safety. As agencies begin the transition, the industry will watch closely to see how the new policy shapes the security landscape for criminal‑justice information across the United States.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related