CJIS Security Policy
The CJIS Security Policy is the FBI's set of minimum security requirements for anyone who accesses, processes, stores or transmits criminal justice information (CJI) from FBI Criminal Justice Information Services systems, including state and local agencies and the private companies that support them.
Its modernized control set follows the NIST SP 800-53 families and borrows its authenticator rules from NIST SP 800-63B. For identity teams, the headline requirement is multi-factor authentication for every privileged and non-privileged account with access to CJI, plus a compromised-password list checked quarterly and a minimum user-chosen password length of 8 characters. Version 6.1, effective June 26, 2026, is a corrections release that clarifies authentication cross-references, requires incidents to be reported immediately rather than after confirmation, and raises symmetric encryption for CJI to 256-bit. The MFA requirements are Priority 1 and sanctionable now; lower-priority requirements stay auditable but not sanctionable until September 30, 2027.
See also: CJIS Security Policy requirements, NIST SP 800-63, MFA, FedRAMP
Related on Start with Identity
- GlossaryStrong Customer Authentication (SCA)
The PSD2 requirement that electronic payment authentication use at least two of: knowledge, possession, inherence. Plus dynamic linking, the auth factor must be
- GlossaryAuthenticator Assurance Level (AAL)
NIST 800-63B levels describing authentication strength. AAL1: single factor. AAL2: multi-factor. AAL3: multi-factor with phishing-resistant cryptographic authen
- GlossaryCIBA
Client-Initiated Backchannel Authentication. An OpenID Connect flow where authentication is initiated on one device and approved on another, useful for call cen
- BlogEntra ID stops delivering SMS and voice codes on February 1, and global admins go last
From February 1, 2027, Microsoft stops providing SMS and voice authentication in Entra ID, and users with no other method must register a passkey to keep signin
- CVEOkta Verify for Windows local privilege escalation
Okta Verify on Windows could be turned into a local privilege escalation. The MFA app on the endpoint is part of the identity plane. Pair with Okta's 2024 FastP
- BlogThe SMS off-ramp has a date now: what Entra, GOV.UK and America.gov mean for your MFA plan
Microsoft stops delivering SMS and voice codes in Entra ID on February 1, 2027. The UK has put passkeys in front of 23 million citizens, and the new federal fro