CJIS Media Protection & Sanitization 2 — Questions and Answers
Question 1: What encryption standard must removable media meet when used to transport CJI outside of a physically secure location, per the CJIS Security Policy?
- AES-128 encryption validated under FIPS 140-2
- FIPS 140-2 or FIPS 140-3 validated encryption using AES-256 (Correct answer)
- RSA-2048 public key encryption for file-level protection
- Triple DES (3DES) encryption with a 112-bit key
Correct answer: FIPS 140-2 or FIPS 140-3 validated encryption using AES-256
The CJIS Security Policy requires CJI transported on removable media to be encrypted using FIPS 140-2 (or 140-3) validated modules with AES-256 to ensure data confidentiality.
Question 2: Which of the following best describes the CJIS Security Policy definition of 'media' in the context of media protection?
- Only digital storage devices such as hard drives, USB drives, and optical discs
- Any physical item that can store CJI, including digital storage devices and paper documents (Correct answer)
- Only removable media such as USB drives, CDs, and external hard drives
- Only cloud-based storage locations where CJI is backed up
Correct answer: Any physical item that can store CJI, including digital storage devices and paper documents
CJIS defines media broadly to include any physical item capable of storing CJI—both electronic/digital storage and paper or printed records—ensuring comprehensive protection requirements.
Question 3: When CJI media must be transported from one agency location to another, what is the primary CJIS requirement?
- Transport must only occur via U.S. Postal Service Certified Mail
- The media must be protected from unauthorized access throughout transport using encryption or physical controls (Correct answer)
- Transport must be approved in writing by the FBI's CJIS Division before departure
- The media must be physically escorted by at least two sworn law enforcement officers
Correct answer: The media must be protected from unauthorized access throughout transport using encryption or physical controls
CJIS requires that CJI media be protected from unauthorized access during transport, typically through encryption, locked containers, or other controls ensuring confidentiality and integrity.
Question 4: An agency wants to donate old computers previously used to access CJI to a local school. What must occur FIRST before the computers leave agency control?
- The agency must obtain a donation permit from the state CJIS Systems Agency
- All storage media in the computers must be sanitized or physically destroyed to remove CJI (Correct answer)
- The agency must install monitoring software so donated computers can still be audited
- The computers must be reformatted using only FBI-approved sanitization software
Correct answer: All storage media in the computers must be sanitized or physically destroyed to remove CJI
Before computers that stored CJI leave agency control for any reason, all storage media must be sanitized using an approved method or physically destroyed to prevent unauthorized access to CJI.
Question 5: What is the CJIS Security Policy requirement for media containing CJI that is sent to a third-party vendor for repair?
- The vendor must be on the FBI's approved vendor list and sign an NDA
- CJI must be removed or sanitized from the media before it is sent to the vendor, or the vendor must operate under an appropriate agreement with security controls (Correct answer)
- The media can be sent only if the vendor is located within the United States
- The agency must notify the FBI's CJIS Division of any media sent to third parties
Correct answer: CJI must be removed or sanitized from the media before it is sent to the vendor, or the vendor must operate under an appropriate agreement with security controls
CJIS requires that CJI be removed or sanitized before media goes to a third-party vendor, or the vendor must be bound by appropriate agreements and security controls to protect the CJI.
Question 6: Under CJIS media protection requirements, which of the following accurately describes an 'overwriting' sanitization technique?
- Physically grinding storage platters into fine particles to destroy data
- Writing new data patterns over existing data to make the original data unrecoverable (Correct answer)
- Using cryptographic erasure to decrypt a drive's encryption key, making data inaccessible
- Applying a strong magnetic field to disrupt magnetic storage domains
Correct answer: Writing new data patterns over existing data to make the original data unrecoverable
Overwriting replaces stored data with new data patterns (e.g., zeros, ones, or random data) across all addressable locations, preventing recovery of the original CJI through software-based means.
Question 7: How does the CJIS Security Policy address the disposal of optical media (CDs/DVDs) that contain CJI?
- Optical media must be degaussed before disposal
- Optical media must be physically destroyed since it cannot be overwritten or degaussed (Correct answer)
- Optical media can be reused after reformatting using approved software
- Optical media containing CJI must be stored indefinitely and never disposed of
Correct answer: Optical media must be physically destroyed since it cannot be overwritten or degaussed
Optical media cannot be effectively sanitized through overwriting or degaussing, so CJIS requires physical destruction (e.g., shredding or disintegration) to prevent recovery of CJI.
What encryption standard must removable media meet when used to transport CJI outside of a physically secure location, per the CJIS Security Policy?