CJIS Mobile Device & Cloud Security 3 — Questions and Answers
Question 1: A cloud provider storing CJI experiences a data breach. Under CJIS Security Policy, the criminal justice agency must:
- Allow the cloud provider to manage breach notification independently
- Notify the FBI CJIS Division and affected individuals per policy timelines (Correct answer)
- Conduct an internal audit before notifying any external parties
- Transfer all CJI to on-premises storage before filing any report
Correct answer: Notify the FBI CJIS Division and affected individuals per policy timelines
CJIS Policy requires agencies to report security incidents involving CJI to the FBI CJIS Division and comply with applicable breach notification requirements.
Question 2: Which control does CJIS Policy require to prevent unauthorized apps from accessing CJI on mobile devices?
- Whitelisting approved applications through MDM policy (Correct answer)
- Requiring users to manually delete unapproved apps monthly
- Blocking app stores at the network firewall level
- Mandating that devices run only factory-default applications
Correct answer: Whitelisting approved applications through MDM policy
CJIS Policy supports application whitelisting via MDM to ensure only approved applications can run on devices that access or store CJI.
Question 3: Under CJIS Security Policy, which personnel must complete CJIS Security Awareness Training before accessing CJI through a cloud system?
- Only sworn law enforcement officers
- All personnel and contractors with access to CJI, regardless of role (Correct answer)
- Only IT administrators managing cloud infrastructure
- Cloud provider employees who hold Top Secret clearance
Correct answer: All personnel and contractors with access to CJI, regardless of role
CJIS Policy requires all personnel — including contractors and cloud provider staff with unescorted access to CJI — to complete security awareness training within six months of assignment.
Question 4: What is the CJIS requirement for authenticating users who access CJI from mobile devices over a public network?
- Single-factor authentication with a complex password is sufficient
- Advanced Authentication (AA) such as multi-factor authentication is required (Correct answer)
- Biometric-only authentication satisfies CJIS mobile access requirements
- Authentication is not required if the device uses full-disk encryption
Correct answer: Advanced Authentication (AA) such as multi-factor authentication is required
CJIS Policy requires Advanced Authentication (AA), typically multi-factor authentication, for accessing CJI over a public network from any device including mobile.
Question 5: An agency's MDM solution flags a mobile device as jailbroken. According to CJIS Security Policy best practices, the agency should:
- Re-image the device and return it to service after 30 days
- Allow limited read-only CJI access until the device is inspected
- Immediately block the device from accessing CJI and investigate (Correct answer)
- Notify the device manufacturer and await their guidance
Correct answer: Immediately block the device from accessing CJI and investigate
A jailbroken device bypasses security controls and cannot be trusted to protect CJI; CJIS Policy requires that non-compliant devices be denied access until remediated.
Question 6: Which CJIS Security Policy section governs the use of cloud computing for storing or processing CJI?
- Section 5.1 — Policy Area 1: Information Exchange Agreements
- Section 5.13 — Policy Area 13: Mobile Devices
- Section 5.10 — Policy Area 10: Systems and Communications Protection (Correct answer)
- Section 5.4 — Policy Area 4: Auditing and Accountability
Correct answer: Section 5.10 — Policy Area 10: Systems and Communications Protection
Cloud computing security for CJI falls under Policy Area 10 (Systems and Communications Protection), which addresses network security and cloud requirements.
Question 7: When a criminal justice agency terminates a contract with a cloud provider, what must occur regarding stored CJI?
- CJI must be archived by the provider for seven years post-termination
- The provider must certify destruction of all CJI per CJIS media sanitization standards (Correct answer)
- CJI ownership transfers to the cloud provider for compliant archival
- The agency must retrieve all CJI within 90 days and no further action is needed
Correct answer: The provider must certify destruction of all CJI per CJIS media sanitization standards
Upon contract termination, the cloud provider must sanitize all media containing CJI in accordance with CJIS media protection and disposal standards.
A cloud provider storing CJI experiences a data breach.
Under CJIS Security Policy, the criminal justice agency must: