A cloud provider storing CJI experiences a data breach. Under CJIS Security Policy, the criminal justice agency must:
-
A
Allow the cloud provider to manage breach notification independently
-
B
Notify the FBI CJIS Division and affected individuals per policy timelines
-
C
Conduct an internal audit before notifying any external parties
-
D
Transfer all CJI to on-premises storage before filing any report