CJIS Interagency Data Sharing Protocols 3 — Questions and Answers
Question 1: A county sheriff's office wants to share criminal history data with a child protective services agency. Under CJIS policy, what must be established first?
- Legislative authority permitting the sharing with that non-criminal justice agency (Correct answer)
- A shared IT infrastructure agreement
- Mutual law enforcement officer certifications
- A joint data warehouse
Correct answer: Legislative authority permitting the sharing with that non-criminal justice agency
Sharing CJI with non-criminal justice agencies like child protective services requires specific legislative or regulatory authority authorizing that disclosure.
Question 2: In the CJIS tiered access model, what determines whether an agency can access III (Interstate Identification Index) records?
- Statutory authorization and a signed user agreement with the state repository (Correct answer)
- Completion of CJIS awareness training only
- Having an active MOU with any other law enforcement agency
- Federal employment status of requesting officers
Correct answer: Statutory authorization and a signed user agreement with the state repository
III access requires both statutory authorization to receive criminal history records and a signed user agreement with the state criminal history repository.
Question 3: Which scenario represents a CJIS policy violation in interagency data sharing?
- An officer emails unencrypted arrest records to a prosecutor's office over public internet (Correct answer)
- A detective verbally requests a record check from a neighboring jurisdiction
- An agency uses a VPN to transmit CJI to a partner agency
- A dispatcher shares wanted person data over an encrypted CAD system
Correct answer: An officer emails unencrypted arrest records to a prosecutor's office over public internet
Transmitting unencrypted CJI over public networks violates CJIS encryption requirements, regardless of recipient agency.
Question 4: How often must agencies that share CJI conduct security audits of their data-sharing partners under CJIS guidelines?
- At least every three years (Correct answer)
- Annually
- Every five years
- Only upon initial agreement signing
Correct answer: At least every three years
CJIS policy requires compliance audits of agencies sharing CJI at a minimum every three years to ensure ongoing adherence to security standards.
Question 5: A federal agency shares CJI with a state agency for a joint task force. Which party is responsible for user training compliance?
- Each agency is responsible for training its own personnel (Correct answer)
- The federal agency trains all task force members
- The state CSO trains all members regardless of affiliation
- The FBI CJIS Division provides all required training directly
Correct answer: Each agency is responsible for training its own personnel
Each participating agency in a joint task force remains responsible for ensuring its own personnel complete required CJIS security awareness training.
Question 6: What is the maximum retention period for CJI transaction logs used to audit interagency data exchanges?
- A minimum of one year (Correct answer)
- 90 days
- Six months
- Seven years
Correct answer: A minimum of one year
CJIS policy requires that transaction logs and audit records related to CJI access be retained for a minimum of one year.
Question 7: When a private contractor accesses CJI on behalf of a criminal justice agency, under whose CJIS agreement does the contractor operate?
- The criminal justice agency that contracted them (Correct answer)
- Their own independent contractor agreement with the FBI
- The state where the contractor is headquartered
- The contractor's parent company's agreement
Correct answer: The criminal justice agency that contracted them
Private contractors accessing CJI operate under the criminal justice agency's CJIS agreement and must comply with all applicable CJIS security requirements.
A county sheriff's office wants to share criminal history data with a child protective services agency.
Under CJIS policy, what must be established first?