CJIS Interagency Data Sharing Protocols 2 — Questions and Answers
Question 1: Under CJIS policy, which document formally establishes the terms and conditions for sharing criminal justice information between two agencies?
- Memorandum of Understanding (MOU) (Correct answer)
- Standard Operating Procedure (SOP)
- Privacy Impact Assessment (PIA)
- Data Classification Matrix
Correct answer: Memorandum of Understanding (MOU)
A Memorandum of Understanding (MOU) formally documents the agreed-upon terms, responsibilities, and conditions for sharing CJI between agencies.
Question 2: When a local police department shares NCIC data with a federal agency, which party bears primary responsibility for ensuring the receiving agency meets CJIS security requirements?
- The originating agency (Correct answer)
- The FBI CJIS Division
- The state CSO
- The receiving agency's IT department
Correct answer: The originating agency
The originating agency is responsible for ensuring that any agency receiving CJI meets the applicable CJIS security requirements before data is shared.
Question 3: A tribal law enforcement agency wants to access NCIC through a state system. What is the required first step?
- Execute a written access agreement with the state agency (Correct answer)
- Submit a request directly to the FBI
- Obtain federal certification independently
- Install FBI-approved encryption software
Correct answer: Execute a written access agreement with the state agency
Tribal agencies must execute a written access agreement with the state agency that will serve as the conduit for NCIC access.
Question 4: Which CJIS principle limits shared criminal justice information to the specific purpose for which it was originally requested?
- Purpose limitation (Correct answer)
- Data minimization
- Need-to-know doctrine
- Least privilege access
Correct answer: Purpose limitation
Purpose limitation restricts the use of CJI to only the specific criminal justice purpose for which the data was originally requested and shared.
Question 5: A state agency discovers that a local department it shares CJI with has suffered a data breach. What must the state agency do immediately?
- Notify the FBI CJIS Division within the required timeframe (Correct answer)
- Suspend all data sharing with all agencies
- Conduct an independent forensic audit
- Issue a public press release about the breach
Correct answer: Notify the FBI CJIS Division within the required timeframe
CJIS policy requires prompt notification to the FBI CJIS Division when a breach involving CJI is discovered, within mandated reporting timeframes.
Question 6: Which type of agency is NOT authorized to directly query the National Crime Information Center (NCIC)?
- Private security firms (Correct answer)
- State police agencies
- Municipal police departments
- Federal law enforcement agencies
Correct answer: Private security firms
Private security firms do not have direct NCIC query access as they are not criminal justice agencies under CJIS definitions.
Question 7: When sharing CJI across state lines, which standard governs the encryption requirements for data in transit?
- FIPS 140-2 validated encryption (Correct answer)
- AES-128 minimum standard
- SSL/TLS 1.0 compliant protocols
- Agency-defined encryption policies
Correct answer: FIPS 140-2 validated encryption
CJIS policy requires FIPS 140-2 validated encryption for all CJI transmitted across public networks, including interstate transmissions.
Under CJIS policy, which document formally establishes the terms and conditions for sharing criminal justice information between two agencies?