LEIN Data Security & Privacy Protocols 4 — Questions and Answers
Question 1: Under LEIN security policy, what is the minimum standard for passwords used to access LEIN terminals?
- 6 characters with no complexity requirements
- 8 characters minimum with complexity requirements including letters and numbers (Correct answer)
- Any agency-defined format as long as it is changed annually
- Biometric authentication is required; passwords are prohibited
Correct answer: 8 characters minimum with complexity requirements including letters and numbers
FBI CJIS Security Policy mandates passwords of at least 8 characters with complexity requirements for systems accessing criminal justice information.
Question 2: A LEIN operator inadvertently queries the wrong person's record due to a name similarity. Under protocol, the operator should:
- Ignore the error since no data was deliberately misused
- Document the error and report it to the TAC per agency policy (Correct answer)
- Notify the incorrectly queried subject about the error
- Delete the query log entry to correct the system record
Correct answer: Document the error and report it to the TAC per agency policy
Inadvertent queries must be documented and reported to the TAC so the agency maintains accurate audit records and can assess any privacy impact.
Question 3: Which of the following scenarios represents an appropriate use of LEIN's Interstate Identification Index (III)?
- Running a background check on a job applicant for a private company
- Checking a suspect's criminal history prior to an interview during an active investigation (Correct answer)
- Verifying an employee's qualifications for a promotion within the police department
- Conducting a preemployment check at the request of a hospital
Correct answer: Checking a suspect's criminal history prior to an interview during an active investigation
III queries are authorized for criminal justice purposes such as active investigations, not non-criminal justice employment screening without proper authorization.
Question 4: What must a LEIN terminal agency do when it experiences a data breach that may have exposed CJIS information?
- Conduct an internal investigation and resolve it quietly to avoid public panic
- Immediately notify MSP-CJIC and follow the CJIS Security Policy breach notification procedures (Correct answer)
- Wait 72 hours to assess the scope before notifying any parties
- Only notify affected individuals, not the state or federal oversight agencies
Correct answer: Immediately notify MSP-CJIC and follow the CJIS Security Policy breach notification procedures
CJIS Security Policy requires immediate notification to the state CSO (MSP-CJIC) upon discovering a security breach involving CJI.
Question 5: Under LEIN policy, the 'need-to-know' principle means that LEIN information may only be accessed when:
- An officer holds a rank of sergeant or above
- There is a specific, articulable law enforcement purpose for the query (Correct answer)
- The subject of the query has a prior criminal record
- The query is approved in advance by a supervisor
Correct answer: There is a specific, articulable law enforcement purpose for the query
The need-to-know principle restricts LEIN access to situations where there is a specific, documented law enforcement justification for each query.
Question 6: A LEIN message containing sensitive personal information is printed and left on a shared printer in a public area. This violates which security principle?
- Chain of custody
- Physical security and media protection (Correct answer)
- Two-factor authentication
- Data minimization at the query stage
Correct answer: Physical security and media protection
Leaving printed LEIN output unsecured in accessible areas violates physical security and media protection requirements under CJIS Security Policy.
Question 7: How frequently must LEIN terminal agency coordinators (TACs) ensure that operator access lists are reviewed and updated?
- Every 5 years at license renewal
- At least annually, or whenever personnel changes occur (Correct answer)
- Only when directed by MSP-CJIC during an audit
- Every 3 years in alignment with CJIS policy review cycles
Correct answer: At least annually, or whenever personnel changes occur
TACs must review and update authorized user lists at least annually and immediately when operators leave or change roles to prevent unauthorized access.
Under LEIN security policy, what is the minimum standard for passwords used to access LEIN terminals?