FBI’s CJIS v6.1: What Security Teams Need to Know.

FBI’s CJIS v6.1: What Security Teams Need to Know.
CJIS Security Policy v6.1 updates the modernized framework with stronger encryption requirements, monthly vulnerability scanning, and continued emphasis on identity, MFA, and password controls for protecting Criminal Justice Information. Organizations should confirm current audit expectations with their CSA and close identity gaps now rather than waiting for controls to become sanctionable. #CJIS #NISTSP80053 #SpecopsPasswordPolicy #SpecopsSecureAccess #SpecopsDeviceTrust #MichiganStatePolice #TexasCSAs

Keypoints

  • CJIS v6.1 raises encryption requirements for CJI in transit and at rest to at least 256-bit strength.
  • Vulnerability scanning frequency changes from quarterly to at least monthly.
  • Agencies must verify audit expectations with their CSA because phased sanction dates still apply.
  • MFA and password controls remain central, with no major change to the Identification and Authentication requirements.
  • Audits are increasingly focused on continuous evidence that controls are working, not just on having the controls in place.

Read More: https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/