Skip to main content

811 - CJIS Access, Maintenance, and Security

811.1 PURPOSE AND SCOPE

The purpose of this policy is to provide guidelines for the use, maintenance, and security of office systems that access, process, store, or transmit Criminal Justice Information.

811.1.1 DEFINITIONS

Criminal Justice Information (CJI) — Data provided by FBI Criminal Justice Information Services (CJIS) that is necessary for law enforcement agencies to perform their mission and enforce the laws (e.g., biometric, identity history, person, organization, case/incident history data).

Security incident — Any incident that compromises the security of CJI or systems that access, process, store, or transmit CJI. Examples include but are not limited to unauthorized use of legitimate code or credentials within office systems, email communications that contain malicious code, data breaches, signaling to external systems, and unauthorized exporting of information.

811.2 POLICY

It is the policy of the Hartwell County Sheriff’s Department to maintain the security, confidentiality, and integrity of its information systems that access, process, store, or transmit CJI by collaborating with appropriate state and federal agencies to implement the applicable established protocols.

811.3 CJIS COORDINATOR

The Sheriff shall appoint a CJIS coordinator, who shall be responsible for the Hartwell County Sheriff’s Department's adherence to FBI CJIS Security Policy requirements.

The CJIS coordinator shall establish procedures necessary to govern the office's use, maintenance, and security of systems that access CJI as described in this policy.

811.3.1 CJIS COORDINATOR RESPONSIBILITIES

The responsibilities of the CJIS coordinator include but are not limited to:

  • Coordinating with others, such as the information technology or legal departments, as appropriate, to maintain office compliance with FBI CJIS Security Policy requirements and the California Justice Information Services.
  • Managing member accounts with access to CJI, including:
  1. Creating, enabling, modifying, disabling, and removing member accounts in accordance with this policy and the FBI CJIS Security Policy.
  2. Configuring member accounts in accordance with federal and state requirements (e.g., limiting unsuccessful login attempts, validating new passwords against known compromised or commonly used passwords).
  3. Reviewing member accounts for compliance with legal and policy requirements at least annually.
  • Overseeing the maintenance, repair, and replacement of CJI systems and system components in accordance with manufacturer or vendor specifications and/or office requirements, including:
  1. Maintaining a list of organizations and personnel approved by the Sheriff to perform maintenance on CJI systems.
  2. Approving, scheduling, documenting, and monitoring all maintenance and diagnostic activities, whether performed on-site, remotely, or off-site, and maintaining records.
  3. Verifying that non-escorted personnel performing maintenance on any CJI system or terminal possess the required access authorizations, and designating members who have the required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.
  4. Maintaining records for all system maintenance and diagnostic activities.
  • Configuring remote access systems and devices only with the explicit authorization of the Sheriff or the authorized designee, including:
  1. Routing through authorized and managed access control points (e.g., firewalls, secure gateways).
  2. Mandatory multi-factor authentications for users.
  3. Use of automated mechanisms to monitor and control remote access methods.
  4. Mandatory encryption (e.g., VPN, Transport Layer Security).
  5. Required logging of all remote access activity.
  • Monitoring office systems that have access to CJI to ensure compliance with applicable laws and this policy; developing processes to detect, identify, and correct flaws in software and firmware; and conducting security updates as necessary. (f) Providing for the security of hardware that includes provisions for the following:
  1. How hardware is to be brought into and taken out of office facilities
  2. Physical security of hardware within office facilities
  3. Physical security of areas containing network connections and transmission lines, including monitored access
  • Implementing and carrying out the office Incident Response Plan, including:
  1. Tracking and documenting all suspected or actual security incidents related to CJI in an appropriate manner.
  2. Directing annual testing of the office's information security incident response capabilities using tabletop or walk-through exercises, simulations, or other types of testing.
  3. Making the appropriate notifications outside of the Office (see the Records Maintenance and Release Policy for additional guidance).
  4. Providing information on security incidents to any third-party software developers or vendors as appropriate.
  • Protecting digital and non-digital media that contain CJI, including physical security, transportation, destruction/sanitization, and documentation requirements.
  • Developing and updating office information security and privacy literacy training and incident response training as required by policy.
  • Maintaining audit records in accordance with the established records retention schedule, but in no event for less than one year.
  • Managing the development, documentation, and dissemination of applicable policies and procedures for the following:
  1. Access Control
  2. Awareness and training
  3. Auditing and accountability
  4. Assessment, authorization, and monitoring
  5. Configuration management
  6. Contingency planning
  7. Identification and authentication
  8. Incident response
  9. Maintenance
  10. Media protection
  11. Physical and environmental protection
  12. Planning
  13. Personnel security
  14. Risk assessment
  15. Systems and services acquisition
  16. Systems and communications protection
  17. System and information integrity
  18. Supply chain risk management
  • Reviewing this policy and related procedures as required by the FBI CJIS Security Policy and proposing updates as needed to the Sheriff.

811.4 MEMBER RESPONSIBILITIES

All members of the Office shall be committed to detecting information security incidents and making the appropriate notifications.

Any member who suspects that there may have been unauthorized access, disclosure, or other compromise of CJI shall report their suspicions in accordance with the Incident Response Plan within one hour of the discovery.

Personally owned devices or systems and publicly accessible systems shall not be used to access, process, store, or transmit CJI.

811.5 SUPERVISOR RESPONSIBILITIES

Supervisors shall notify the CJIS coordinator when the account access of a member they supervise needs to be modified, disabled, or removed for any reason, such as resignation, termination, or change of duties.

811.6 MEMBER ACCOUNTS

Office accounts used to access CJI shall only be created upon approval of the Sheriff or the authorized designee.

Member accounts shall be disabled within one week of any of the following:

  • The account has expired.
  • The account is no longer associated with a member.
  • The account is found to be in violation of this policy.
  • The account has been inactive for 90 calendar days.

If any threat to the confidentiality, integrity, or availability of CJI related to a specific member account is detected, the CJIS coordinator or designated member shall disable the account within 30 minutes of the discovery.

811.6.1 ACCESS AUTHORIZATION

Access authorization for systems transmitting, receiving, using, or storing CJI shall be based on the principle of least privilege as follows:

  • Members shall only be granted access authorizations that are necessary to accomplish assigned office tasks.
  • Accounts with security privileges shall only be authorized for members with an operational need for the privileges. Privileged functions shall be logged as they are executed.
  • Non-privileged members shall not be allowed to execute privileged functions.

811.6.2 ACCOUNT REVIEW ACTIVITIES

At least annually, the CJIS coordinator shall review member accounts for compliance with policy and applicable laws. The CJIS coordinator shall validate account privileges and remove or reassign them as necessary to accurately reflect the office mission and law enforcement needs. 811.7 MEDIA PROTECTION Access to media containing CJI shall be restricted to authorized members and stored within physically secured locations or controlled areas, in accordance with the FBI CJIS Security Policy.

Digital media (e.g., flash drives, external or removable hard disk drives, compact discs) containing CJI shall be encrypted. Personally owned digital media devices or digital media devices with no identifiable owner shall not be used on office systems that store, process, or transmit CJI.

Non-digital media (e.g., paper files, printed pages, microfilm) containing CJI should be enclosed in an opaque folder or container if they are to be transported outside of physically secure locations or controlled areas. Media containing CJI shall not be left unattended outside of a physically secure location.

Transportation and transfers of media containing CJI shall only be conducted by authorized members and shall be documented.

811.7.1 MEDIA DISPOSAL AND RELEASE

Digital media containing CJI shall be overwritten at least three times or degaussed (i.e., erased) prior to being disposed of, released from office control, or released for reuse.

Inoperable digital media devices, such as hard drives or solid-state drives that cannot be accessed to overwrite the data, shall be physically destroyed. When non-digital media is no longer needed for investigative or security purposes, it shall be destroyed by crosscut shredding or incineration.

811.8 SYSTEM AND INFORMATION INTEGRITY

The integrity of office CJI systems shall be protected through the implementation of appropriate controls such as:

  • Flaw remediation.
  • System monitoring.
  • Security alerts, advisories, and directives.
  • Software, firmware, and information integrity controls.
  • Spam protection.

811.9 INCIDENT RESPONSE PLAN

[Insert your agency's Incident Response Plan consistent with CJIS 5.3 IR-4, IR-7, and IR-8 – see the Guide Sheet for additional guidance.]

811.10 SECURITY AWARENESS TRAINING

Members with physical or electronic access to CJI or CJI systems shall complete security awareness training appropriate to their assigned roles and responsibilities and shall certify their understanding by signing a formal Security Awareness Training Acknowledgement. Training shall include information security and privacy literacy training, security incident response training, and a review of this policy and related procedures.

Security awareness training shall be completed prior to accessing any CJI data or system and at least annually thereafter. Additional training shall be completed as required following any changes to CJI systems and for any member involved in a security incident within 30 days of the event.

Individual training records shall be maintained in accordance with the established records retention schedule, but in no event for less than three years.

The office's CJIS training shall be reviewed for any necessary updates or changes annually and following any security incident or change in a CJI system or the FBI CJIS Security Policy.

811.11 SANCTIONS

Failure to adhere to policies and procedures pertaining to CJI shall result in disciplinary action, up to and including termination. Misuse of or failure to secure CJI may also result in temporary or permanent restrictions in the use of CJI. Intentional misuse of CJI may also be prosecutable under applicable laws.