CJIS Security Policy Compliance Standard (SFA 06-107.2.7)

Summary

Requirements for protecting Criminal Justice Information (CJI) in line with the FBI CJIS Security Policy, including access control, multi-factor authentication, personnel background screening, media protection, physical security, and audits; applies primarily to the University Police Department and supports Policy 06-107.2.

Body

Quick Overview
  • This standard sets the security requirements SFA must meet to access and protect Criminal Justice Information (CJI), such as criminal history records from FBI and Texas law-enforcement systems.
  • It follows the FBI CJIS Security Policy (v6.0) and the rules of the Texas Department of Public Safety (Texas DPS), and carries out the goals in the SFA 06-107.2 Information Security Technology Policy.
  • It applies mainly to the SFA University Police Department (UPD) and the IT staff who support systems that handle CJI, plus any contractors or vendors with CJI access.
  • Key protections include multi-factor authentication (MFA), fingerprint-based background checks, encryption of CJI, physically secure locations, and audits every three years.
  • Meeting this standard is mandatory. Falling short can cost SFA its access to criminal justice systems.

Whenever SFA looks up a criminal history, runs a name through a law-enforcement database, or stores information from these systems, it is handling Criminal Justice Information (CJI). The FBI and the State of Texas require every agency that touches CJI to protect it in very specific ways. This standard translates those national rules, the FBI CJIS Security Policy version 6.0, into concrete requirements for SFA so that the University Police Department and the IT staff who support it can keep this access and keep the information safe from unauthorized use, disclosure, or loss.

i
Policy vs. Standard
The matching policy (06-107.2) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps will live in procedures.

Who This Applies To

This standard applies to all SFA personnel, contractors, and vendors who access, view, process, store, transmit, or support systems that handle Criminal Justice Information (CJI), including criminal history record information from FBI systems (such as NCIC, III, and N-DEx) or the Texas equivalents administered by Texas DPS (TLETS/TCIC). In practice, it centers on the SFA University Police Department (UPD), the primary criminal justice agency at SFA, and the Office of Information Security and IT Services (ITS) staff who administer, host, or support the systems, networks, and facilities that CJI passes through. It covers every workstation, server, cloud service, mobile device, and physically secure location involved with CJI.

i
Baseline, not a ceiling
Everything here is the minimum SFA must do. Where the FBI CJIS Security Policy, Texas DPS requirements, or TAC 202 differ, the most restrictive rule wins. UPD and the Office of Information Security may add stricter controls, but never anything weaker.

Who Is Responsible

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person. CJIS work also relies on two law-enforcement roles, the LASO and the TAC, described below.
  • SFA Chief Information Security Officer (CISO): The senior security authority for SFA. Makes sure CJI systems are governed in line with the CJIS Security Policy, TAC 202, and UT System requirements; approves this standard; secures resources for compliance and fixing audit findings; and coordinates with UPD, legal, and the Texas DPS CJIS Systems Officer (CSO).
  • Local Agency Security Officer (LASO): Designated by UPD as the security point of contact between SFA and the Texas DPS CJIS Systems Agency (CSA). Tracks who uses approved hardware and software, keeps the CJI network diagram current, confirms security screening and controls are in place, and supports incident reporting and audits.
  • Terminal Agency Coordinator (TAC): UPD's liaison to Texas DPS for TLETS/TCIC operations. Administers system access, oversees operator certification and record validations, maintains agreements and rosters, and coordinates the audit response with the LASO and CISO.
  • SFA University Police Department (UPD): The criminal justice agency responsible for lawful use of CJI at SFA. Maintains the agreements, physically secure locations, and procedures; designates the LASO and TAC; ensures personnel meet clearance and training rules; owns CJI incident response; and cooperates with Texas DPS and FBI audits.
  • Personnel with CJI access: All employees, contractors, and vendors authorized to handle CJI. Must complete training before access and every two years after, pass a fingerprint background check, use only authorized devices and accounts with MFA, protect CJI in every form, and report suspected incidents immediately.
Full role definitions Complete responsibilities for each role are in the attached standard PDF.

What This Standard Requires

The requirements are grouped into thirteen areas that line up with the CJIS Security Policy's Policy Areas. Expand any area for a plain-language summary of what it requires. The official requirement numbers (like 06-107.2.7.1.1) are shown so you can match them to the attached PDF.

1  Information Exchange Agreements & Governance  The paperwork that permits access ⌄

SFA must keep the right agreements, appointments, and system records in place before CJI can be shared.

  • Keep current written agreements with Texas DPS and partner agencies that spell out permitted uses, controls, and audit rights, reviewed at least yearly (06-107.2.7.1.1).
  • Require the FBI CJIS Security Addendum, and a management control or outsourcing agreement, before any contractor or vendor touches CJI (06-107.2.7.1.2).
  • Formally designate a LASO and a TAC in writing, notify the CSA, and train them within six months (06-107.2.7.1.3).
  • Maintain an accurate inventory and network diagram of every system, connection, and secure location that handles CJI (06-107.2.7.1.4).
2  Security Awareness Training  Teaching people the rules ⌄

Everyone who touches CJI must be trained before they start and kept current afterward.

  • Complete CJIS security awareness training before gaining access, then refresh it at least every two years; no training means no access (06-107.2.7.2.1).
  • Cover the essentials: protecting and sharing CJI, spotting and reporting incidents, media and physical protection, passwords, phishing, and the penalties for noncompliance (06-107.2.7.2.2).
  • Keep auditable records of who trained, when, and on what, and produce them during formal audits (06-107.2.7.2.3).
3  Incident Response  When something goes wrong ⌄

SFA must be ready to detect, contain, and report any compromise of CJI, and report it fast.

  • Maintain a documented CJI incident response capability covering detection, containment, recovery, and follow-up, tied into the University incident process (06-107.2.7.3.1).
  • Report any suspected incident immediately to UPD and the LASO, who notifies Texas DPS (and the FBI as directed) within required timeframes; do not wait to investigate first (06-107.2.7.3.2).
  • Document, track, and retain records of each incident, and preserve evidence for any CSA or FBI review (06-107.2.7.3.3).
  • Test the incident response plan at least yearly, update it from lessons learned, and report results to the CISO (06-107.2.7.3.4).
4  Auditing & Accountability  Keeping a record of activity ⌄

CJI systems must log who did what, keep those logs safe, and review them regularly.

  • Record security-relevant events, including logons, privileged actions, permission changes, and access to CJI, capturing what, when, who, source, and outcome (06-107.2.7.4.1).
  • Keep logs at least one year, protect and back them up, and synchronize system clocks to an authoritative time source (06-107.2.7.4.2).
  • Review logs at least weekly for unusual activity, escalate suspected incidents, and document the review, using automated alerting where feasible (06-107.2.7.4.3).
5  Access Control & Least Privilege  Only the right people, only what they need ⌄

Access to CJI is limited to authorized people, kept to the minimum needed, and controlled tightly.

  • Grant access only on a least-privilege, need-to-know basis, documented and approved by UPD and reviewed at least yearly (06-107.2.7.5.1).
  • Use unique accounts per person (no shared logins), and promptly disable accounts on separation, transfer, lost clearance, or long inactivity (06-107.2.7.5.2).
  • Enforce session locks after inactivity and limit concurrent sessions and failed logon attempts (06-107.2.7.5.3).
  • Explicitly authorize, restrict, and encrypt remote access through monitored access points; do not use public or personal systems for CJI unless expressly permitted (06-107.2.7.5.4).
6  Identification & Authentication (MFA)  CJIS v6.0  Proving who you are ⌄

Every user must be uniquely identified and must use multi-factor authentication (MFA) to reach CJI. This is a CJIS Priority 1 rule, enforceable since October 1, 2024.

  • Uniquely identify each user and process and authenticate them before access; keep authenticators individually assigned and protected (06-107.2.7.6.1).
  • Require MFA for all CJI access, using at least two independent factors (something you know, have, or are); maintain compliant MFA and remediate gaps under a documented plan (06-107.2.7.6.2).
  • Where passwords are used, meet CJIS v6.0 password standards (aligned with NIST SP 800-63B), and prefer phishing-resistant methods like PKI or FIDO2, especially for privileged access (06-107.2.7.6.3).
  • Require MFA on privileged and admin accounts, separate them from routine accounts, and add enhanced monitoring and approval-based elevation (06-107.2.7.6.4).
7  Configuration Management  Building systems securely & keeping them that way ⌄

CJI systems must be set up to a secure baseline, changed carefully, and patched promptly.

  • Maintain documented secure baseline configurations and hardening that disables unnecessary services, ports, and features (06-107.2.7.7.1).
  • Manage changes through review, testing, approval, and rollback, and restrict configuration changes to authorized staff (06-107.2.7.7.2).
  • Apply security patches on a timely, risk-based basis, and keep a current inventory of hardware, software, and firmware supporting the network diagram (06-107.2.7.7.3).
8  Media Protection  Protecting CJI on drives, paper & disks ⌄

CJI on any media, digital or physical, must be stored securely, protected in transit, and destroyed safely.

  • Store CJI media in controlled areas, restricted to authorized people and handled according to its sensitivity (06-107.2.7.8.1).
  • Protect CJI in transit with encryption (digital) and controlled, documented handling (physical), accounting for it during transport (06-107.2.7.8.2).
  • Sanitize or destroy media by approved methods before reuse or disposal, and document (and witness where required) the action (06-107.2.7.8.3).
9  Physical Protection  Physically secure locations ⌄

CJI may only be used in physically secure locations with controlled entry, logged access, and escorted visitors.

  • Access, process, and store CJI only in physically secure locations with defined perimeters and controlled entry points, documented by UPD (06-107.2.7.9.1).
  • Authorize, log, and periodically review physical access; issue keys, cards, and codes on a need basis and revoke them promptly (06-107.2.7.9.2).
  • Identify, authorize, escort, and monitor visitors at all times, and position screens and printouts so CJI cannot be viewed by others (06-107.2.7.9.3).
10  Systems & Communications Protection  Encryption, firewalls & monitoring ⌄

CJI must be encrypted, CJI networks must be walled off and watched, and threats must be caught and fixed.

  • Encrypt CJI in transit outside a secure location and at rest using FIPS-validated modules meeting CJIS strength requirements (06-107.2.7.10.1).
  • Protect CJI network boundaries with firewalls and segmentation, allowing only explicitly permitted traffic (06-107.2.7.10.2).
  • Run malware protection, intrusion detection, and continuous monitoring, keeping detection current and escalating alerts to incident response (06-107.2.7.10.3).
  • Monitor security advisories and remediate vulnerabilities within risk-based timeframes, validating that fixes work (06-107.2.7.10.4).
11  Personnel Security  Fingerprint background checks ⌄

Everyone with CJI access must pass a fingerprint-based background check before access, with re-screening and prompt removal when needed.

  • Complete a state and national fingerprint-based background check, favorably adjudicated, before any CJI access is granted (06-107.2.7.11.1).
  • Re-screen periodically and on any sign of disqualifying conduct; deny or revoke access under CJIS criteria and notify the LASO/TAC (06-107.2.7.11.2).
  • On termination, transfer, or change of duties, immediately revoke access, recover credentials and property, and apply sanctions for violations (06-107.2.7.11.3).
12  Mobile Devices  Laptops, tablets, phones & patrol terminals ⌄

Mobile devices that reach CJI must be managed, encrypted, and remotely wipeable, and personal devices are off-limits unless approved.

  • Authorize, inventory, and centrally manage mobile devices (including in-vehicle terminals) through MDM that enforces configuration, encryption, and policy (06-107.2.7.12.1).
  • Enforce MFA, device encryption, session lock, and remote lock/wipe; report any loss or theft immediately (06-107.2.7.12.2).
  • Encrypt wireless and cellular connections carrying CJI; do not allow personally owned (BYOD) devices unless fully brought under MDM and this standard (06-107.2.7.12.3).
13  Formal Audits  The triennial CJIS audit ⌄

Texas DPS and the FBI audit SFA's CJIS compliance at least every three years, and SFA must self-check in between and fix any findings.

  • Cooperate fully with the triennial (at least once every three years) formal CJIS audits by Texas DPS and the FBI, coordinated by UPD, the LASO, and the TAC (06-107.2.7.13.1).
  • Run internal self-assessments between audits to catch gaps against CJIS v6.0 priority controls, reporting results to the CISO and UPD leadership (06-107.2.7.13.2).
  • Track audit findings in a corrective action plan with owners and dates, keeping P1 controls compliant and P2-P4 controls on track for the October 1, 2027 deadline (06-107.2.7.13.3).

Conformance & Exceptions

Meeting this standard is mandatory for all SFA personnel, contractors, and vendors with access to CJI. It is issued under the authority of SFA 06-107.2 and TAC 202 and implements the FBI CJIS Security Policy v6.0. Where this standard, the CJIS Security Policy, Texas DPS requirements, or TAC 202 differ, the most restrictive requirement governs. If a requirement genuinely cannot be met, exceptions must be documented, risk-assessed, and approved in writing by the SFA Chief Information Security Officer (CISO) in coordination with UPD and, where required, the CSA, with compensating controls and a remediation timeline.

!
Important
Multi-factor authentication and other Priority 1 controls have been enforceable and auditable since October 1, 2024, and full compliance with Priority 2 through Priority 4 controls is required by October 1, 2027. Noncompliance can result in loss of CJI access, University disciplinary action, and CJIS sanctions, up to termination of the agency's access to FBI CJIS systems and possible civil or criminal penalties.

Compliance Mapping (Reference)

For auditors and security staff. Everyday users can skip this section.

Frameworks & control references ⌄

Each requirement in this standard maps to one or more of these authoritative sources:

  • FBI CJIS Security Policy v6.0 (effective December 27, 2024), which realigns the traditional 13 Policy Areas to the control families of NIST 800-53 Revision 5.
  • NIST 800-53 Rev 5, for example the AC, AT, AU, IA, IR, MP, PE, PS, SC, SI, CM, and CA control families.
  • NIST 800-63B, Digital Identity Guidelines, for password and authentication requirements.
  • TAC 202, Texas Administrative Code Title 1, Chapter 202, Information Security Standards, for example 202.71, 202.74, 202.76.

The full requirement-by-requirement control mapping is in the attached standard PDF and the FBI CJIS Security Policy to NIST SP 800-53 Rev. 5 controls mapping.

Related Policies & Standards

Supporting policy: SFA 06-107.2 Information Security Technology Policy

Related standards:

Other references:

  • FBI CJIS Security Policy v6.0 (effective December 27, 2024)
  • NIST SP 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organizations
  • NIST SP 800-63B, Digital Identity Guidelines (Authentication)
  • Texas DPS CJIS resources and Texas CJIS Systems Agency (CSA) requirements

Responsible office: SFA University Police Department; Office of Information Security  ·  Contact: itsecurity@sfasu.edu

📎
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this standard, contact the Office of Information Security at itsecurity@sfasu.edu.

Details

Details

Article ID: 173945
Created
Fri 7/17/26 12:15 PM
Modified
Fri 7/17/26 12:48 PM

Related Articles

Related Articles (2)

Requirements for governing SFA's security program, including the security strategy, documentation, leadership roles, planning and reporting, system inventory, and the insider-threat and research-security programs; supports Policy 06-107.1.
Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.