CJIS Security Policy 6.1 – Understanding the Changes

Summary:   The FBI Criminal Justice Information Services (CJIS) recently released the latest minor update to the CJIS Security Policy, the document which sets the foundation for cyber security programs for law enforcement.  In this article we discuss the changes and highlight implications for any organization that must comply with CJIS.

Summary of Changes V6 to V6.1

The CJIS Security Policy 6.1 is primarily a maintenance release.  This means there were no substantial changes to overall structure and requirements, such as the major change between V5 and V6.  However, 6.1 had updates of five key areas that will impact any a cyber governance program for CJIS.

Six Key Changes in CJIS Security Policy 6.1

CJIS 6.1 Security Policy

CJIS 6.1 Policy Update

More Frequent Vulnerability Scans

The first key change was to RA-5 VULNERABILITY MONITORING AND SCANNING and SI-2 (Flaw Remediation), where the Vulnerability scanning frequency increased from quarterly to monthly.  Of all the 6.1 changes, this will likely have the most impact on a CJIS Governance Program.   

RA-5 VULNERABILITY MONITORING AND SCANNING [Priority 1]

Control: a. Monitor and scan for vulnerabilities in the system and hosted applications at least monthly and when new vulnerabilities potentially affecting the system are identified and reported;

The control change requires an update to any formal scanning and review cadence.  For some agencies it may require an updated license to any commercial Vulnerability scanning tools. 

Stronger Encryption Requirements

The second key change was in SC-13 (Cryptographic Protection), formally increasing the Minimum symmetric encryption key strength raised from 128-bit to 256-bit, for Criminal Justice Information (CJI) both in transit and at rest.

SC-13 CRYPTOGRAPHIC PROTECTION [Existing] [Priority 2]

Control:

a. Determine the use of encryption for CJI in-transit when outside a physically secure location; and

b. Implement the following types of cryptography required for each specified cryptographic use: cryptographic modules which are Federal Information Processing Standard (FIPS) 140-3 certified, or a FIPS validated algorithm for symmetric key encryption and decryption (FIPS 197 [AES]), with a symmetric cipher key of at least 256-bit strength for CJI in-transit.

Again, any Agency security policies and standards should be modified with the new requirements.  Any tool that evaluates agency compliance against these thresholds is producing incorrect pass/fail results until updated.

Incident Reporting Notifications

There are two fundamental changes to the Incident Reporting function that will have an impact on the CJIS cyber security program.

First, in IR-6 (Incident Reporting), CJIS now requires reporting to the FBI CJIS ISO, in addition to the CSO, SIB Chief, and Interface Agency Official.

Second, the Incident Reporting Control wording changed to drop the “if confirmed” qualifier, which means that now all incidents must be reported, not only “confirmed” ones.

IR-6 INCIDENT REPORTING [Priority 2]

Control: a. Require personnel to report suspected incidents to the organizational incident response capability immediately but not to exceed one (1) hour after discovery; and

 b. Report incident information to organizational personnel with incident handling responsibilities, and the CSO, SIB Chief, or Interface Agency Official, and FBI CJIS ISO.

These changes will require any Incident Response Policies and Procedures to be updated to reflect the new reporting requirements.   Also, if the agency has any “standard” for determining that an incident is “confirmed” to trigger a notification, this can be updated with the new requirement.

Personnel Training and Awareness

The most significant changes that impact personnel security are in AT-3 (Role-Based Training). The 6.1 policy update revised the training requirements for each role, which has a direct impact on security awareness and training content required for CJIS.

The new training requirements imply that all targeted CJIS 6.0 Security Awareness Training must be updated to match the new requirements.

Another new “note” within the training Control specifies that the CSO/SIB Chief may now accept documentation of role-based training completed at another agency, with the accepting agency assuming the risk that the training may not meet applicable requirements.

AT-3 Role-Based Training (new note): The CSO/SIB Chief may now accept documentation of role-based training completed at another agency, with the accepting agency assuming the risk that the training may not meet applicable requirements.

 This expanded option creates a new opportunity for cost savings by being able to accept training and certification from other Agencies.  This is especially important when it comes to Vendors employees, who are often serving multiple agencies at once.

Information Security Organization

The major change within the Information Security Organization is that now Controls can be assigned to an individual “team member” instead of just an individual.  For example, in AC-1, IA-1, IR-1, MA-1, MP-1, PE-1 the wording changes from:  “Designate an individual with security responsibilities” to “Designate organizational personnel with information security responsibilities.”  This removes the requirement for a single, named individual, which now allows more efficient delegation. 

IA-1 POLICY AND PROCEDURES [Priority 2]

b. Designate organizational personnel with information security responsibilities to manage the development, documentation, and dissemination of the identification and authentication policy and procedures; and [  ]

This change requires that all information security policies and related control in these domains can be updated to reflect the new option for delegation to other team members.

Note:  Updating these controls is an opportunity to formally identify members of the Information Security team that can accept these assignments.

Other Minor CJIS 6.1 Control Changes

In addition to the major changes illustrated above, many of the Controls were modified with grammar fixes, refined requirements and cross references to V6.0 naming.  While these are minor changes, they may still impact the details of the governance program.  The following Control areas had updates or clarifications:

  • PE-2 (Physical Access Authorizations): “Controlling ingress and egress” narrowed to “controlling ingress” only — explicit egress-control language was dropped.

  • AC-2 (Account Management): “Identity Provider Id” removed from the list of required account attributes.

  • IA-5 (Authenticator Management): FIPS 140 verifier requirement narrowed to apply specifically to federal government agencies (previously “government agencies” generally).

  • MP-6 (Media Sanitization): Sanitization method mapping reorganized — non-digital media (renamed from “physical” media) is now specifically what must be crosscut-shredded or incinerated, separated out from digital media handling.

CJIS 6.1 Update: Recommended Next Steps

Based on the changes, here are some key next steps for updating your CJIS Security Program to 6.1 Requirements.

  • Review existing encryption key strength and patch verification controls and cadence.  Any tool that evaluates agency compliance against these thresholds is producing incorrect pass/fail results until updated.

  • Confirm with the compliance/policy team whether previously "compliant" agency records under the old encryption and patch-cadence thresholds should be re-flagged for re-assessment. 

  • Review and update Incident Response Policies and procedures to reflect the new reporting requirements in IR-6.   Add specific contact details for the appropriate FBI contact.

  • Review all Control ID references throughout the framework.  For example, Control ID references throughout the policy were normalized; any tool logic keyed to legacy section numbers needs a mapping update to avoid broken references or mis-scored assessments.

Staying Up to Date with Peak Performance Solutions

Fundamental changes to the CJIS Security Policy can place a large burden on compliance teams.  Qualified team members can spend many hours sifting through the details, trying to interpret any meaningful changes and how to act on them.

Peak GRC (Governance, Risk and Compliance) is a product design specifically to reduce this compliance burden.  One of the key features of Peak GRC is a set of CJIS Security Control Frameworks, a set of CJIS Controls all mapped to the CJIS Security Policy.   When the CJIS Security Policy changes, we keep all the information up to date.  Peak GRC also has a complete set of CJIS Security Policy Templates, all mapped to the CJIS Security Policy requirements.   These templates form the foundation for any CJIS Governance Program, and just one part of a complete tool to streamline CJIS compliance.

Peak CJIS Online (CJO) is our CJIS security awareness and training platform.  It enables any Agency to streamline the entire process of personnel certification. Just as we do with GRC, the Peak team updates each of the training requirements – so you don’t have to.

Give Us a Try

Peak Performance has been a trusted partner in the Law Enforcement community for over 30 years, with over 60,000 Agency customers in all 50 states.   Using Peak Performance, your staff can skip painful administrative tasks and get back to what they do best: law enforcement. Contact Peak Sales today to request more information or a free trial.

Next
Next

What is CJIS 6.0?