CJIS Mobile Device & Cloud Security 2 — Questions and Answers
Question 1: Under CJIS Security Policy, what is required before a mobile device can access CJI via a cellular network?
- The device must use a VPN or equivalent encryption tunnel (Correct answer)
- The device must be registered with the FBI directly
- Only WPA2 Wi-Fi connections are permitted for CJI access
- Cellular access requires a dedicated government SIM card
Correct answer: The device must use a VPN or equivalent encryption tunnel
CJIS Policy requires that CJI transmitted over cellular networks be protected by an advanced authentication and encryption mechanism equivalent to a VPN tunnel.
Question 2: Which CJIS requirement applies specifically to tablets and smartphones used to access CJI?
- They must run only FIPS 140-2 validated operating systems
- They must enforce a session lock after no more than 30 minutes of inactivity
- They must be agency-issued and prohibited from personal use
- They must display a CJIS warning banner upon login (Correct answer)
Correct answer: They must display a CJIS warning banner upon login
CJIS Policy mandates that any system accessing CJI display an approved warning banner notifying users of monitoring and authorized-use restrictions.
Question 3: A law enforcement officer's personal smartphone is used to access agency email containing CJI. Which CJIS control is most directly triggered?
- Media protection controls requiring sanitization before disposal
- Mobile Device Management (MDM) enrollment and policy enforcement (Correct answer)
- Physical protection requiring locked storage when unattended
- Background investigation requirements for civilian contractors
Correct answer: Mobile Device Management (MDM) enrollment and policy enforcement
CJIS Policy requires that personally owned devices accessing CJI be enrolled in an MDM solution that enforces agency security policies.
Question 4: What does CJIS Policy require regarding the remote wipe capability of mobile devices that store or access CJI?
- Remote wipe must be tested annually and documented
- Remote wipe capability must be enabled and enforceable by the agency (Correct answer)
- Remote wipe is optional if the device uses full-disk encryption
- Remote wipe must be performed within 48 hours of device loss
Correct answer: Remote wipe capability must be enabled and enforceable by the agency
CJIS Policy requires agencies to have the ability to remotely wipe mobile devices that access CJI to protect against unauthorized disclosure after loss or theft.
Question 5: Under CJIS cloud computing requirements, which party bears responsibility for ensuring the cloud service meets CJIS Security Policy standards?
- The cloud service provider, who must self-certify compliance
- The FBI CJIS Division, which audits all cloud providers annually
- The criminal justice agency using the cloud service (Correct answer)
- NIST, which maintains the cloud security framework
Correct answer: The criminal justice agency using the cloud service
The criminal justice agency remains responsible for ensuring any cloud provider they contract with meets CJIS Security Policy requirements, typically via an executed CJIS Security Addendum.
Question 6: Which cloud deployment model is explicitly addressed in CJIS Security Policy as requiring a CJIS Security Addendum with the provider?
- Private cloud hosted solely within agency data centers
- Community cloud shared only among law enforcement agencies
- Public cloud services offered by commercial vendors (Correct answer)
- Hybrid cloud combining on-premises and private infrastructure
Correct answer: Public cloud services offered by commercial vendors
CJIS Policy specifically requires a signed CJIS Security Addendum when using public cloud services where CJI may be stored or processed.
Question 7: What encryption standard does CJIS Policy require for CJI stored on mobile devices?
- AES-128 minimum with software-based encryption
- FIPS 140-2 validated encryption (Correct answer)
- TLS 1.2 applied at the application layer
- RSA-2048 for all stored criminal justice data
Correct answer: FIPS 140-2 validated encryption
CJIS Policy requires that CJI stored on mobile devices be protected using FIPS 140-2 validated encryption modules.
Under CJIS Security Policy, what is required before a mobile device can access CJI via a cellular network?