CJIS Physical Security Requirements 2 — Questions and Answers
Question 1: Under CJIS Security Policy, which type of area requires the most stringent physical security controls for systems processing CJI?
- Publicly accessible lobby
- Controlled area with badge readers
- Physically secure location with two-factor entry (Correct answer)
- Restricted area with sign-in logs only
Correct answer: Physically secure location with two-factor entry
CJIS requires a physically secure location with at least two-factor authentication for areas where CJI is processed.
Question 2: What is the minimum requirement for escorting visitors in a CJIS-defined physically secure location?
- Visitors may move freely with a visitor badge
- Visitors must be escorted at all times by authorized personnel (Correct answer)
- Visitors need only check in at a front desk
- Visitors are allowed unescorted access to non-server areas
Correct answer: Visitors must be escorted at all times by authorized personnel
CJIS policy requires that visitors in physically secure locations be escorted at all times by authorized personnel.
Question 3: Which control is specifically required to detect unauthorized physical access attempts to areas containing CJI systems?
- Motion-sensor lights
- Intrusion detection systems (Correct answer)
- Posted security guards only
- Periodic manual audits
Correct answer: Intrusion detection systems
CJIS requires intrusion detection systems to monitor and alert on unauthorized physical access to CJI areas.
Question 4: A local police department stores backup CJI media in a locked filing cabinet outside the secure area. What CJIS requirement does this violate?
- Audit log retention
- Encryption standards
- Physical protection of media in transit or at rest (Correct answer)
- User training requirements
Correct answer: Physical protection of media in transit or at rest
CJIS requires CJI media to be physically protected whether in transit or at rest, including secure storage within authorized areas.
Question 5: How often must physical security controls for CJIS facilities be reviewed according to the CJIS Security Policy?
- Every five years
- Only when a breach occurs
- At least every three years or when significant changes occur (Correct answer)
- Monthly by facility staff
Correct answer: At least every three years or when significant changes occur
CJIS requires physical security controls to be reviewed at least every three years or whenever significant changes occur.
Question 6: Which of the following is an acceptable form of two-factor authentication for entry into a CJIS physically secure location?
- PIN plus a security question
- Badge plus biometric scan (Correct answer)
- Username plus password
- Photo ID presented to a guard
Correct answer: Badge plus biometric scan
A badge (something you have) plus a biometric scan (something you are) constitutes valid two-factor authentication for physical access.
Question 7: What must be done with physical access logs for CJIS-compliant facilities?
- Logs are optional if video surveillance is in place
- Logs must be retained for at least one year (Correct answer)
- Logs must be destroyed after 30 days to protect privacy
- Logs are only required for server rooms
Correct answer: Logs must be retained for at least one year
CJIS Security Policy requires physical access logs to be retained for a minimum of one year to support audits and investigations.
Under CJIS Security Policy, which type of area requires the most stringent physical security controls for systems processing CJI?