CJIS Policies & Compliance Standards 3 — Questions and Answers
Question 1: Under CJIS policy, who bears ultimate responsibility for ensuring compliance within a criminal justice agency?
- The IT Security Officer
- The Terminal Agency Coordinator
- The Agency Head (Chief or Director) (Correct answer)
- The FBI CJIS Division
Correct answer: The Agency Head (Chief or Director)
The agency head, such as the chief of police or director, bears ultimate responsibility for ensuring the agency's compliance with the CJIS Security Policy.
Question 2: What does the CJIS Security Policy identify as the required baseline encryption standard for protecting CJI at rest?
- 3DES (Triple DES)
- AES 128-bit or higher (Correct answer)
- RC4 256-bit
- RSA 1024-bit
Correct answer: AES 128-bit or higher
CJIS policy requires AES 128-bit or higher (FIPS 140-2 validated) encryption for protecting CJI stored at rest.
Question 3: A law enforcement agency wants to use a cloud service provider to store CJI. What is the FIRST step the agency must take?
- Obtain FBI approval for the cloud vendor
- Ensure the CSP signs the CJIS Security Addendum (Correct answer)
- Perform a vulnerability scan of the cloud environment
- Notify all officers whose data will be stored
Correct answer: Ensure the CSP signs the CJIS Security Addendum
Before using a cloud service provider for CJI, the provider must execute the CJIS Security Addendum to be contractually bound to CJIS requirements.
Question 4: Which of the following is NOT a required element of a CJIS-compliant incident response plan?
- Procedures for containing the incident
- A list of all CJI data stored on-site (Correct answer)
- Procedures for reporting the breach to the CSA
- Mechanisms for recovering affected systems
Correct answer: A list of all CJI data stored on-site
While an inventory of CJI is a good practice, a static list of stored data is not a required element of the incident response plan itself under CJIS policy.
Question 5: How does the CJIS Security Policy define 'Criminal Justice Information' (CJI)?
- All records maintained by a law enforcement agency
- The abstract term for all FBI-managed databases
- All information from the III, NCIC, and other CJIS systems needed for law enforcement (Correct answer)
- Only biometric data used in criminal investigations
Correct answer: All information from the III, NCIC, and other CJIS systems needed for law enforcement
CJI refers to the information from CJIS systems such as the III, NCIC, and others that is necessary for law enforcement and criminal justice purposes.
Question 6: Under the CJIS Security Policy, multi-factor authentication (MFA) is required when accessing CJI from:
- Any location, regardless of network type
- Only from mobile devices
- Locations outside the physically secure location (Correct answer)
- Only when connecting via VPN
Correct answer: Locations outside the physically secure location
MFA is mandatory when accessing CJI from outside a physically secure location, such as from remote or public locations.
Question 7: Which CJIS policy controls the requirement that all personnel with access to CJI must complete security awareness training?
- Personnel Security Policy
- Awareness and Training Policy (Correct answer)
- Access Control Policy
- Configuration Management Policy
Correct answer: Awareness and Training Policy
The Awareness and Training Policy mandates that all personnel with access to CJI receive security awareness training within six months of hire and every two years thereafter.
Under CJIS policy, who bears ultimate responsibility for ensuring compliance within a criminal justice agency?