CJIS Data Management & Record Keeping 2 — Questions and Answers
Question 1: Under CJIS policy, what is the maximum retention period for audit logs related to criminal justice information access?
- 1 year
- 3 years (Correct answer)
- 5 years
- 7 years
Correct answer: 3 years
CJIS policy requires audit logs to be retained for a minimum of 3 years to support investigations and compliance reviews.
Question 2: Which data classification level applies to CHRI (Criminal History Record Information) under CJIS policy?
- Public
- Sensitive But Unclassified
- Controlled Unclassified Information (CUI) (Correct answer)
- Top Secret
Correct answer: Controlled Unclassified Information (CUI)
CHRI is classified as Controlled Unclassified Information (CUI), requiring specific handling and protection controls.
Question 3: When a record in the III (Interstate Identification Index) contains an error, who bears primary responsibility for correcting it?
- The FBI CJIS Division
- The originating state or agency (Correct answer)
- The NCIC Compact Council
- The receiving agency that detected the error
Correct answer: The originating state or agency
The originating agency that submitted the record is responsible for making corrections to ensure data accuracy.
Question 4: What does the term 'hot file' refer to in the context of NCIC data management?
- A file containing encrypted biometric data
- An active record flagged for immediate law enforcement attention (Correct answer)
- A temporary cache of recent queries
- A file scheduled for purging within 30 days
Correct answer: An active record flagged for immediate law enforcement attention
A 'hot file' in NCIC contains active records such as wanted persons or stolen property that require immediate action when matched.
Question 5: Which requirement governs how agencies must handle CJIS data stored on decommissioned hardware?
- Data must be encrypted before disposal
- Storage media must be sanitized using NIST 800-88 guidelines (Correct answer)
- Hard drives must be returned to the FBI
- Data must be migrated to cloud backup before decommission
Correct answer: Storage media must be sanitized using NIST 800-88 guidelines
CJIS policy requires media sanitization in accordance with NIST SP 800-88 to prevent unauthorized data recovery.
Question 6: Under CJIS policy, secondary dissemination of criminal justice information to a non-criminal justice agency requires what?
- Approval from the state CJIS Systems Officer
- A written agreement and logging of the dissemination (Correct answer)
- Prior authorization from the FBI Director
- Encryption of the data before transfer
Correct answer: A written agreement and logging of the dissemination
Secondary dissemination must be documented in a written agreement and logged to maintain an auditable chain of information sharing.
Question 7: A law enforcement agency receives a positive hit on a wanted person record. Before taking action, what must the agency verify?
- The age of the record in NCIC
- Confirmation with the originating agency (Correct answer)
- The subject's criminal history going back 10 years
- That the record was entered by a certified operator
Correct answer: Confirmation with the originating agency
Agencies must confirm hits with the originating agency before acting to ensure the record is still valid and accurate.
Under CJIS policy, what is the maximum retention period for audit logs related to criminal justice information access?