CJIS Training & Awareness Programs 3 — Questions and Answers
Question 1: Under CJIS policy, which category of personnel is exempt from completing security awareness training?
- Contracted IT vendors with CJI access
- Sworn officers with over 10 years of service
- Civilian dispatch staff
- No personnel with CJI access are exempt (Correct answer)
Correct answer: No personnel with CJI access are exempt
CJIS Security Policy requires ALL personnel who access CJI — regardless of role, rank, or tenure — to complete security awareness training.
Question 2: A CJIS security awareness program should include which type of scenario-based training element?
- Role-playing budget negotiations
- Simulated social engineering attempts and proper responses (Correct answer)
- Speed-typing exercises for terminal input
- Customer service conflict resolution
Correct answer: Simulated social engineering attempts and proper responses
Scenario-based training including simulated social engineering helps personnel recognize and appropriately respond to real-world threats to CJI security.
Question 3: Which CJIS policy section specifically governs the requirements for personnel security and training?
- Section 4 — Physical Protection
- Section 5 — Policy and Implementation
- Section 6 — Personnel Security (Correct answer)
- Section 9 — Incident Response
Correct answer: Section 6 — Personnel Security
Section 5 of the CJIS Security Policy covers Personnel Security, including background screening and awareness training requirements.
Question 4: When a CJIS agency undergoes a triennial compliance audit, what training-related documentation must be available?
- Only the training curriculum outline
- Completed training records for all personnel with CJI access (Correct answer)
- Instructor certifications from state academies only
- Future training schedules and planned content
Correct answer: Completed training records for all personnel with CJI access
During audits, agencies must produce completed training records demonstrating that all CJI-authorized personnel have satisfied awareness training requirements.
Question 5: A law enforcement agency contracts with a private company to manage its records management system containing CJI. What training requirement applies to the contractor's employees?
- No training required since they are not sworn officers
- Training only if they are on-site at the agency
- The same CJIS security awareness training as agency personnel (Correct answer)
- Training is the contractor's sole responsibility without agency oversight
Correct answer: The same CJIS security awareness training as agency personnel
Contractor employees with access to CJI must meet the same security awareness training requirements as direct agency employees under CJIS policy.
Question 6: What does the CJIS Security Policy require agencies to do when a security awareness training curriculum is updated?
- Wait until the next annual cycle to deliver updated content
- Notify personnel via email only without requiring completion
- Ensure personnel are trained on the updated material in a timely manner (Correct answer)
- Archive the old curriculum without replacement
Correct answer: Ensure personnel are trained on the updated material in a timely manner
When training content is updated to reflect new threats or policy changes, agencies must ensure personnel receive and complete the updated training promptly.
Question 7: Which method of CJIS security awareness training delivery is explicitly approved under CJIS policy?
- In-person classroom training only
- Online computer-based training (CBT) modules (Correct answer)
- Verbal briefings with no documentation
- Self-study with no testing component
Correct answer: Online computer-based training (CBT) modules
CJIS policy accepts multiple delivery formats including online computer-based training, provided training is documented and covers required content areas.
Under CJIS policy, which category of personnel is exempt from completing security awareness training?