Governance, risk, and compliance in one place.
Compliance Shield is a complete governance, risk, and compliance tool built specifically for CJIS. Agencies can skip the manual process of documenting, tracking, and validating CJIS controls, and save up to 100 hours preparing for CJIS audits.
What does Compliance Shield do?
Automate the management controls of your security process. Compliance Shield assumes you already have firewalls and MFA — it is the layer that ties policies, controls, evidence, incidents, and vendors together and keeps them current.
Document with policies (5.1)
Create CJIS 6.0 ready security policies with over 20 Security Policy Templates, already mapped to CJIS and NIST controls. Copy a template, auto-fill your organization's details, publish. The mappings stay intact, so you are not guessing whether a policy satisfies anything.
IT risk management (RA)
A guided assessment walks through your assets and the threats against them, asks about likelihood and impact, then produces risk scores and a heat map. Assign mitigations and track them from there.
Store and share evidence (AU)
Evidence is uploaded against the specific control it satisfies and stored encrypted — asset inventories, training records, vendor attestations. When an auditor asks how you meet a requirement, you open the control and the proof is already attached to it.
Build control baselines (PL)
Controls belong to a role and people are assigned to that role. When the person who owned compliance leaves, the program does not quietly fall out of compliance with them — the new person inherits the role and the controls come with it.
Employee acknowledgements (PS)
Policies move through draft, review, published, and archived. Published policies appear in an employee portal where staff formally acknowledge them, and those acknowledgements are stored as evidence against the control they satisfy.
Manage vendor risk (SR)
Categorize vendors by risk, assign the assessment that matches, and let them answer and upload evidence through their own portal. Instead of describing how you manage supplier risk, you show the dashboard.
Manage incidents (IR)
Incident management workflows for documenting and responding to security events, so the response is recorded in the same place as the controls and evidence it relates to.
Track compliance (CA)
Track CJIS compliance across departments, agencies, and the state level, so status is visible without chasing it down.
For local agencies, these capabilities are included in Peak COMMAND.See Peak COMMAND →
How it works
How Compliance Shield works.
01
Define
Choose your security framework
Assign roles and responsibilities to your users
02
Deliver
Policy generation
Task assignment and tracking
Employee compliance tracking
03
Demonstrate
Automated risk assessments
Evidence storage
Risk scoring and compliance gaps
Inside the product
Governance, risk, and compliance from one dashboard.
See policy, controls, and risk at a glance
Generate policy from a library
Run risk assessments automatically
Store evidence against controls
See Compliance Shield for your program
Tell us which framework you baseline against and how you handle evidence today.
More questions about Compliance Shield? See the FAQ →