Training.Certification.Validations.Audits.Governance.
Distribute security awareness training to every agency in your state, certify the people who work in NCIC, run the monthly validation cycle, audit your agencies, and prove your own compliance when the FBI comes to you.
The job
What does a CSA have to manage statewide?
A CJIS Systems Agency is responsible for CJIS within its state. In practice that means providing security awareness training to agencies across the state, administering certification testing for people who query state and national systems, running the monthly NCIC validation cycle, auditing local agencies and contractors, and being ready for the FBI's own audit of the CSA. Each of those has its own cycle, its own records, and its own way of falling behind.
- Security awareness training, every agency
- NCIC certification testing
- Monthly record validation
- Audits of local agencies and contractors
- Readiness for the FBI's audit of the CSA
- Policy, controls, and evidence in between
Which Peak products do states run?
States run Peak à la carte. Start with the products you need and add modules as your program grows.
The industry standard for security awareness training.
Affordable online training and testing that makes it simple to comply with required CJIS security and privacy training for practitioners, operators, vendors, and IT personnel.
Streamline your NCIC certification process.
The market leader in training and tracking State and NCIC certification status, with distinct workflows for Full Admin, Admin, and Assistant Admin user types.
Audit management, digitized.
A complete electronic audit platform for state and federal CSAs. CJIS audits, technical audits, and non-criminal justice agency audits, all in one place.
The first browser-based NCIC validation system.
Import the NCIC validation file and replace printing, mailing, and paper handling with a monthly cycle agencies work in the browser.
Governance, risk, and compliance in one place.
Over 20 pre-written policy templates mapped to CJIS and NIST controls, a risk assessment wizard, and evidence stored against the control it satisfies. An Auditor role is built for external audits by the FBI.
What else can a state add?
Governance, custom training, and cyber readiness, added as your program grows.
Turns CJIS Online into a full learning management system. Upload your own courses, video series, and quizzes alongside standard CJIS content, and assign them to your whole organization, to specific organization units, or to named people.
Explore Peak Training Extension →Eight specialized security courses covering ground that required CJIS training does not. Run them always-on across your workforce, or provision them per incident.
Explore Cyber & IR Training →Extend the products you already run. Each module activates inside your existing platform.
Agency Relationship Management. Targeted messaging, task tracking, and custom agency and user classifications, plus two custom state certifications that auto-assign based on those classifications.
Explore ARM →Agencies upload audit evidence directly through a secure portal. Submissions are time-stamped and automatically linked to the audit, agency, and requirement, which ends the email chains.
Explore Audit Docs →LASO designation, certification testing, compliance tracking, and reporting.
Explore Security Roles →API access and single sign-on. Automates user provisioning, integrates certification data into your systems of record, and adds bulk certificate download.
Explore CJO Access →Ready to see it work for your program?
Tell us how your state runs training, testing, validations, and audits today. We will walk you through how Peak handles each one.
More questions about running CJIS statewide? See the FAQ →