CJIS Security Policy 6.1 — Understanding the Changes
The FBI released a maintenance update to the CJIS Security Policy. Five areas changed in ways that affect any CJIS governance program — here is what to update.

The FBI Criminal Justice Information Services (CJIS) division recently released the latest minor update to the CJIS Security Policy, the document that sets the foundation for cyber security programs in law enforcement. This article covers what changed and what it means for any organization that has to comply.
What changed between 6.0 and 6.1?
Version 6.1 is primarily a maintenance release. There were no substantial changes to the overall structure or requirements, unlike the major shift between version 5 and version 6. That said, 6.1 updated five key areas that will affect any CJIS governance program.
Vulnerability scans move from quarterly to monthly
The first key change is to RA-5 (Vulnerability Monitoring and Scanning) and SI-2 (Flaw Remediation). Scanning frequency increased from quarterly to monthly. Of all the 6.1 changes, this is the one most likely to affect a CJIS governance program day to day.
The control now requires monitoring and scanning for vulnerabilities in the system and hosted applications at least monthly, and whenever new vulnerabilities affecting the system are identified and reported.
This requires an update to any formal scanning and review cadence. For some agencies it may also require an updated license for commercial vulnerability scanning tools.
Encryption strength doubles
The second key change is in SC-13 (Cryptographic Protection). The minimum symmetric encryption key strength has been raised from 128-bit to 256-bit, for criminal justice information both in transit and at rest.
Agency security policies and standards should be modified to reflect the new requirement. Any tool that evaluates agency compliance against these thresholds is producing incorrect pass and fail results until it is updated.
Incident reporting gets broader
Two fundamental changes to incident reporting will affect the CJIS cyber security program.
First, IR-6 (Incident Reporting) now requires reporting to the FBI CJIS ISO in addition to the CSO, SIB Chief, and Interface Agency Official.
Second, the wording dropped the "if confirmed" qualifier. All incidents must now be reported, not only confirmed ones.
Incident response policies and procedures will need updating to reflect the new reporting requirements. If your agency has a standard for determining that an incident is confirmed before triggering a notification, that can be revised.
Role-based training requirements were revised
The most significant personnel security changes are in AT-3 (Role-Based Training). The 6.1 update revised the training requirements for each role, which has a direct impact on the security awareness and training content required for CJIS. Any targeted CJIS 6.0 security awareness training will need to be updated to match.
A new note within the training control specifies that the CSO or SIB Chief may now accept documentation of role-based training completed at another agency, with the accepting agency assuming the risk that the training may not meet applicable requirements.
This creates a real opportunity for cost savings, particularly for vendor employees who often serve several agencies at once.
Security responsibilities can be delegated to a team
The major change within information security organization is that controls can now be assigned to organizational personnel rather than a single named individual. Across AC-1, IA-1, IR-1, MA-1, MP-1 and PE-1, the wording changed from "designate an individual with security responsibilities" to "designate organizational personnel with information security responsibilities."
This allows more efficient delegation. It is also an opportunity to formally identify the members of the information security team who can accept these assignments.
Other minor control changes
Beyond the major changes, many controls were modified with grammar fixes, refined requirements, and cross references to version 6.0 naming. Areas with updates or clarifications include PE-2 (Physical Access Authorizations), where controlling ingress and egress narrowed to controlling ingress only; AC-2 (Account Management), where Identity Provider Id was removed from required account attributes; IA-5 (Authenticator Management), where the FIPS 140 verifier requirement narrowed to federal government agencies specifically; and MP-6 (Media Sanitization), where the sanitization method mapping was reorganized so non-digital media is specifically what must be crosscut shredded or incinerated.
What should you do next?
Based on these changes, here are the practical next steps for updating a CJIS security program to 6.1.
Review existing encryption key strength and patch verification controls and cadence. Any tool evaluating compliance against the old thresholds is producing incorrect results until updated.
Confirm with your compliance or policy team whether records previously marked compliant under the old encryption and patch-cadence thresholds should be re-flagged for reassessment.
Review and update incident response policies and procedures to reflect the new IR-6 reporting requirements, and add specific contact details for the appropriate FBI contact.
Review control ID references throughout your framework. Control ID references were normalized in this release, so any tool logic keyed to legacy section numbers needs a mapping update to avoid broken references or mis-scored assessments.
How Peak helps you stay current
Fundamental changes to the CJIS Security Policy place a real burden on compliance teams. Qualified people can spend many hours sifting through the details, working out which changes are meaningful and how to act on them.
Compliance Shield, Peak's governance, risk and compliance platform, is designed specifically to reduce that burden. It includes CJIS security control frameworks mapped to the CJIS Security Policy, and a complete set of policy templates mapped to those requirements. When the policy changes, Peak keeps the mappings current.
CJIS Online is Peak's security awareness and training platform, covering all four policy roles. As with the GRC platform, Peak updates the training requirements so agencies do not have to.
See where your compliance actually stands
Twenty minutes with our team — your program, mapped onto the platform all 50 states already trust.
Book a demo