CJIS Training & Awareness Programs 2 — Questions and Answers
Question 1: Under CJIS Security Policy, how frequently must personnel with access to CJI complete security awareness training?
- Every 6 months
- Annually (Correct answer)
- Every 2 years
- Only upon initial hire
Correct answer: Annually
The CJIS Security Policy requires security awareness training to be completed at least every two years, but most agencies implement annual training to align with best practices.
Question 2: Which of the following topics is NOT explicitly required in CJIS security awareness training content?
- Proper handling and protection of CJI
- Incident response procedures
- Social media marketing strategies (Correct answer)
- Threats and vulnerabilities to CJI
Correct answer: Social media marketing strategies
Social media marketing strategies have no relevance to CJIS security awareness training, which focuses on CJI protection, threats, incident response, and acceptable use.
Question 3: A new civilian contractor begins work at a police department accessing NCIC terminals. When must their CJIS security awareness training be completed?
- Within 6 months of start date
- Before accessing any CJI (Correct answer)
- Within 30 days of start date
- Upon annual review cycle
Correct answer: Before accessing any CJI
CJIS policy requires that personnel complete security awareness training before being granted access to CJI systems.
Question 4: Who is responsible for ensuring that CJIS security awareness training records are maintained for auditing purposes?
- Individual employees only
- The FBI CJIS Division exclusively
- The Agency Head or their designee (Correct answer)
- The state training academy
Correct answer: The Agency Head or their designee
The Agency Head or their designated security officer is responsible for maintaining training records to demonstrate compliance during CJIS audits.
Question 5: Which scenario best describes a 'need-to-know' violation that CJIS training should address?
- An officer running a plate check on a stolen vehicle
- A detective querying NCIC for a suspect in an active investigation
- An officer looking up a neighbor's criminal history out of personal curiosity (Correct answer)
- A dispatcher verifying a driver's license status during a traffic stop
Correct answer: An officer looking up a neighbor's criminal history out of personal curiosity
Querying CJI for personal curiosity rather than an official law enforcement purpose violates the 'need-to-know' principle central to CJIS policy.
Question 6: What is the primary purpose of the CJIS Security Addendum that personnel must acknowledge?
- To authorize billing for system access
- To certify agreement to safeguard CJI and comply with CJIS policy (Correct answer)
- To request elevated system privileges
- To register personal devices for remote access
Correct answer: To certify agreement to safeguard CJI and comply with CJIS policy
The CJIS Security Addendum is a binding agreement where personnel certify they understand and will comply with CJIS security requirements for protecting CJI.
Question 7: An officer receives a phishing email appearing to come from the state CJIS division requesting login credentials. What is the correct response trained under CJIS awareness programs?
- Reply with credentials since the request appears official
- Click the link to verify its authenticity
- Report the email to the agency's IT security team and do not respond (Correct answer)
- Forward the email to all colleagues to warn them
Correct answer: Report the email to the agency's IT security team and do not respond
CJIS security awareness training instructs personnel to report suspected phishing attempts to IT security and never provide credentials in response to unsolicited requests.
Under CJIS Security Policy, how frequently must personnel with access to CJI complete security awareness training?