CJIS Policies & Compliance Standards 2 — Questions and Answers
Question 1: Under the CJIS Security Policy, how often must agencies conduct a formal security assessment of their information systems?
- Every six months
- Every three years
- Annually (Correct answer)
- Every five years
Correct answer: Annually
The CJIS Security Policy requires agencies to conduct a formal security assessment of their systems at least annually.
Question 2: Which of the following best describes the role of a Terminal Agency Coordinator (TAC) under CJIS policy?
- Manages physical security of the data center
- Serves as the liaison between the agency and the CSA for CJIS matters (Correct answer)
- Approves all CJIS system access requests
- Conducts penetration testing on agency networks
Correct answer: Serves as the liaison between the agency and the CSA for CJIS matters
The TAC serves as the point of contact between the criminal justice agency and the CJIS Systems Agency for all CJIS-related matters.
Question 3: What is the minimum password length required by the CJIS Security Policy for accounts accessing CJI?
- 6 characters
- 8 characters (Correct answer)
- 10 characters
- 12 characters
Correct answer: 8 characters
The CJIS Security Policy mandates a minimum password length of 8 characters for accounts that access Criminal Justice Information.
Question 4: A private contractor processes CJI on behalf of a criminal justice agency. Which agreement MUST be in place before access is granted?
- A Non-Disclosure Agreement (NDA)
- A CJIS Security Addendum (Correct answer)
- An Interagency Data Sharing Agreement
- A Memorandum of Understanding (MOU)
Correct answer: A CJIS Security Addendum
Private contractors must sign the CJIS Security Addendum, which binds them to the same security requirements as criminal justice agencies.
Question 5: Under CJIS policy, how long must agencies retain audit logs for systems that access CJI?
- 30 days
- 90 days
- One year (Correct answer)
- Three years
Correct answer: One year
The CJIS Security Policy requires that audit logs be retained for a minimum of one year to support investigations and compliance reviews.
Question 6: Which CJIS policy area governs the requirements for transmitting CJI over public networks?
- Personnel Security
- Physical Protection
- Encryption and Data-in-Transit (Correct answer)
- Incident Response
Correct answer: Encryption and Data-in-Transit
The Encryption and Data-in-Transit policy area requires that CJI be encrypted using FIPS 140-2 validated algorithms when transmitted over public networks.
Question 7: An agency discovers that a former employee still has active credentials in a CJIS system two weeks after termination. Which policy has been violated?
- Incident Response Policy
- Account Management Policy (Correct answer)
- Physical Security Policy
- Audit and Accountability Policy
Correct answer: Account Management Policy
Account Management Policy requires that access is revoked immediately upon termination, making lingering credentials a direct violation.
Under the CJIS Security Policy, how often must agencies conduct a formal security assessment of their information systems?