CJIS Compliance

Is Your Agency Ready for CJIS Security Policy 6.0?

The FBI's CJIS Security Policy 6.0 introduced stricter controls for agencies that access criminal justice information. BNS helps NC law enforcement and government agencies meet the new requirements.

CJIS 6.0 raises the bar — is your infrastructure current?

CJIS Security Policy 6.0 updated requirements for advanced authentication, encryption, mobile device management, and cloud services. Agencies that haven't reviewed their compliance posture since the update may have gaps they're not aware of. BNS conducts CJIS gap assessments and implements the technical controls required to bring your environment into compliance.

Key CJIS 6.0 requirements BNS addresses

Advanced authentication

CJIS 6.0 requires advanced authentication (AA) for all users accessing CJI, including multi-factor authentication. BNS implements compliant MFA that meets CJIS's specific requirements for authentication factors.

Encryption standards

Data at rest and in transit must use FIPS 140-2 validated encryption. BNS audits your encryption implementation across workstations, mobile devices, and communications channels.

Mobile device management

CJIS-compliant MDM policies for every device that accesses CJI — including automatic screen lock, remote wipe capability, and application control.

Cloud service compliance

Cloud providers accessing CJI must be CJIS-compliant and operate under a CJIS Security Addendum. BNS validates your cloud services meet this requirement.

Audit logging and review

Comprehensive logging of all access to CJI with regular log review procedures. BNS implements centralized log management that satisfies CJIS audit trail requirements.

Security awareness training

All personnel with access to CJI must complete biennial security awareness training. BNS provides CJIS-aligned training and tracks completion for compliance documentation.

Version 6.0 strengthened requirements for advanced authentication, updated encryption standards to align with current FIPS requirements, added mobile device management provisions, and clarified cloud service compliance requirements including mandatory CJIS Security Addendums for cloud providers.
Yes. Any agency or personnel that accesses, processes, stores, or transmits Criminal Justice Information — including CAD systems, dispatch operations, and records management — must comply with the CJIS Security Policy.
Yes, with the right configuration. Microsoft operates under a CJIS Security Addendum for government cloud services (Microsoft 365 Government — GCC or GCC High). Standard commercial Microsoft 365 tenants are not CJIS-compliant. BNS can assess your current tenant and migrate you to the appropriate government tier if needed.
A thorough CJIS gap assessment for a typical municipal agency takes two to four weeks — covering policy review, technical controls, training documentation, and vendor compliance verification. BNS delivers a written gap report with prioritized remediation steps.
No obligation

Get a clear picture of your CJIS compliance gaps

BNS works with NC law enforcement agencies and local governments to assess CJIS compliance and implement required technical controls. Schedule a free readiness review — no sales pressure, just honest answers.