Framework library
Framework module · cjis-security-policy

CJIS Security Policy

The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software.

6.1 · FBI Criminal Justice Information Services · published 2026-06-25

Standing today
Catalog only

01Standing

Catalog only

A directory entry — authority, version ledger, verification — not a workspace you can open.

CJIS Security Policy is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.

le.fbi.gov returns 403 to automated fetch. v6.1 is evidenced by the FBI's own file-repository filename (cjis_security_policy_v6-1_20260625.pdf); read the cover page from a browser session before treating this as primary.

02Registry record

checked 2026-08-06
Registry status
Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Policy areas 1-13 · Access control · Identification and authentication · Audit and accountability · Incident response
Applies to
law enforcement · public safety · government · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
Pending change
The published policy is ahead of the audited one. CJIS audits through 2027-03-31 are still conducted against 5.9.5, and full P2-P4 control compliance is required by 2027-10-01. Quoting 6.1 at an agency that is being audited against 5.9.5 is a real mismatch — say which one you mean.Expected: 2027-10-01 (full P2-P4 compliance)

03Version ledger

3 editions
5.9.5Supersededdate not published
6.0Superseded · supersedes 5.9.52024-12-27
6.1Current edition · supersedes 6.02026-06-25
CJIS Security Policy — framework module | ControlFrame