CJIS Cheat Sheet 2026
The 30 highest-yield CJIS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
50 questions
60 min time limit
80% to pass
- Which scenario violates CJIS record management policy? → Using CHRI results to deny employment without legal authorization
- A fingerprint-based background check using CHRI is considered more reliable than a name-based check because: → It uniquely identifies an individual regardless of name variations
- Which of the following best describes a key competency required for disaster recovery & business continuity in CJIS practice? → Strong analytical skills combined with effective communication and ethical judgment
- A forensic examiner is asked to testify about findings from a disk image. What must be established first to make the evidence admissible? → Foundation for authenticity, including chain of custody and hash verification
- Under CJIS policy, who bears ultimate responsibility for ensuring compliance within a criminal justice agency? → The Agency Head (Chief or Director)
- Which agency is responsible for maintaining the national repository of criminal history records used in CJIS background investigations? → FBI CJIS Division
- What is a key component of incident documentation? → Detailed records
- What is the role of audit trails in data management? → Track changes and access
- An agency discovers that a former employee still has active credentials in a CJIS system two weeks after termination. Which policy has been violated? → Account Management Policy
- Which legal doctrine allows law enforcement to seize digital evidence not specified in a warrant if it is in plain view during lawful execution of the warrant? → Plain view doctrine
- What minimum password length does CJIS Security Policy require for accounts accessing CJI? → 8 characters
- Which CJIS policy requirement applies when criminal justice data is transmitted over a public network? → Data must be encrypted using FIPS 140-2 validated encryption
- What does FIPS 140-2 or FIPS 140-3 validation indicate about an encryption product used with CJI? → The cryptographic module meets federal security standards tested by NIST
- Which CJIS policy area governs the requirements for transmitting CJI over public networks? → Encryption and Data-in-Transit
- Under CJIS Security Policy, what is required before a mobile device can access CJI via a cellular network? → The device must use a VPN or equivalent encryption tunnel
- Which of the following is NOT a required component of a CJIS-compliant incident response plan? → A list of all approved vendors for law enforcement equipment purchases
- Which CJIS requirement governs how long physical access control records (e.g., badge swipe logs) must be retained? → At least 1 year
- What is system auditing used for? → Review activity
- An agency's IT vendor remotely accesses a server that stores CJI. Under CJIS policy, this vendor must: → Be supervised by agency staff and comply with the CJIS Security Addendum
- What action must an agency take when an individual named in an NCIC protection order record reports that the order has been lifted by the court? → Verify the court order modification before clearing the record
- A vendor provides a network appliance that will sit inside the CJIS-connected network. What must the agency verify about the appliance? → Its cryptographic modules must be FIPS 140-2 validated if used for encryption
- How often must CJIS security training be completed? → Annually
- When a CJIS agency relocates its server room, what physical security action must be taken before CJI systems are moved? → Ensure the new location meets CJIS physical security standards before relocation
- What is the first step in incident response? → Identify and report
- What is the purpose of data management? → Organize and maintain data
- Under CJIS policy, what action must be taken if a mobile device containing CJI is lost or stolen? → Immediately report the incident to the CSA and initiate remote wipe if possible
- How does CJIS policy address the use of personally owned devices (BYOD) for accessing CJI? → BYOD must meet the same security controls as agency-owned devices
- What is the maximum time an agency has to enter a wanted person record into NCIC after issuance of a warrant? → 24 hours
- When a CJIS-authorized user's employment is terminated, within what timeframe must their access be revoked? → Immediately upon separation
- What does 'spoliation' of digital evidence refer to? → Destruction or alteration of evidence that may be relevant to litigation
Turn these facts into recall:
Was this helpful?