Compliance Shield

Governance, risk, and compliance in one place.

Compliance Shield is a complete governance, risk, and compliance tool built specifically for CJIS. Agencies can skip the manual process of documenting, tracking, and validating CJIS controls, and save up to 100 hours preparing for CJIS audits.

Capabilities

What does Compliance Shield do?

Automate the management controls of your security process. Compliance Shield assumes you already have firewalls and MFA — it is the layer that ties policies, controls, evidence, incidents, and vendors together and keeps them current.

01

Document with policies (5.1)

Create CJIS 6.0 ready security policies with over 20 Security Policy Templates, already mapped to CJIS and NIST controls. Copy a template, auto-fill your organization's details, publish. The mappings stay intact, so you are not guessing whether a policy satisfies anything.

02

IT risk management (RA)

A guided assessment walks through your assets and the threats against them, asks about likelihood and impact, then produces risk scores and a heat map. Assign mitigations and track them from there.

03

Store and share evidence (AU)

Evidence is uploaded against the specific control it satisfies and stored encrypted — asset inventories, training records, vendor attestations. When an auditor asks how you meet a requirement, you open the control and the proof is already attached to it.

04

Build control baselines (PL)

Controls belong to a role and people are assigned to that role. When the person who owned compliance leaves, the program does not quietly fall out of compliance with them — the new person inherits the role and the controls come with it.

05

Employee acknowledgements (PS)

Policies move through draft, review, published, and archived. Published policies appear in an employee portal where staff formally acknowledge them, and those acknowledgements are stored as evidence against the control they satisfy.

06

Manage vendor risk (SR)

Categorize vendors by risk, assign the assessment that matches, and let them answer and upload evidence through their own portal. Instead of describing how you manage supplier risk, you show the dashboard.

07

Manage incidents (IR)

Incident management workflows for documenting and responding to security events, so the response is recorded in the same place as the controls and evidence it relates to.

08

Track compliance (CA)

Track CJIS compliance across departments, agencies, and the state level, so status is visible without chasing it down.

For local agencies, these capabilities are included in Peak COMMAND.See Peak COMMAND →

How it works

How Compliance Shield works.

01

Define

Choose your security framework

Assign roles and responsibilities to your users

02

Deliver

Policy generation

Task assignment and tracking

Employee compliance tracking

03

Demonstrate

Automated risk assessments

Evidence storage

Risk scoring and compliance gaps

Inside the product

Governance, risk, and compliance from one dashboard.

See policy, controls, and risk at a glance

Generate policy from a library

Run risk assessments automatically

Store evidence against controls

See Compliance Shield for your program

Tell us which framework you baseline against and how you handle evidence today.

More questions about Compliance Shield? See the FAQ →