Criminal Justice Information Services (CJIS) Security Policy
Total Page:16
File Type:pdf, Size:1020Kb
U. S. Department of Justice Federal Bureau of Investigation Criminal Justice Information Services Division Criminal Justice Information Services (CJIS) Security Policy Version 5.5 06/01/2016 CJISD-ITS-DOC-08140-5.5 Prepared by: CJIS Information Security Officer Approved by: CJIS Advisory Policy Board EXECUTIVE SUMMARY Law enforcement needs timely and secure access to services that provide data wherever and whenever for stopping and reducing crime. In response to these needs, the Advisory Policy Board (APB) recommended to the Federal Bureau of Investigation (FBI) that the Criminal Justice Information Services (CJIS) Division authorize the expansion of the existing security management structure in 1998. Administered through a shared management philosophy, the CJIS Security Policy contains information security requirements, guidelines, and agreements reflecting the will of law enforcement and criminal justice agencies for protecting the sources, transmission, storage, and generation of Criminal Justice Information (CJI). The Federal Information Security Management Act of 2002 provides further legal basis for the APB approved management, operational, and technical security requirements mandated to protect CJI and by extension the hardware, software and infrastructure required to enable the services provided by the criminal justice community. The essential premise of the CJIS Security Policy is to provide appropriate controls to protect the full lifecycle of CJI, whether at rest or in transit. The CJIS Security Policy provides guidance for the creation, viewing, modification, transmission, dissemination, storage, and destruction of CJI. This Policy applies to every individual—contractor, private entity, noncriminal justice agency representative, or member of a criminal justice entity—with access to, or who operate in support of, criminal justice services and information. The CJIS Security Policy integrates presidential directives, federal laws, FBI directives and the criminal justice community’s APB decisions along with nationally recognized guidance from the National Institute of Standards and Technology. The Policy is presented at both strategic and tactical levels and is periodically updated to reflect the security requirements of evolving business models. The Policy features modular sections enabling more frequent updates to address emerging threats and new security measures. The provided security criteria assists agencies with designing and implementing systems to meet a uniform level of risk and security protection while enabling agencies the latitude to institute more stringent security requirements and controls based on their business model and local needs. The CJIS Security Policy strengthens the partnership between the FBI and CJIS Systems Agencies (CSA), including, in those states with separate authorities, the State Identification Bureaus (SIB). Further, as use of criminal history record information for noncriminal justice purposes continues to expand, the CJIS Security Policy becomes increasingly important in guiding the National Crime Prevention and Privacy Compact Council and State Compact Officers in the secure exchange of criminal justice records. The Policy describes the vision and captures the security concepts that set the policies, protections, roles, and responsibilities with minimal impact from changes in technology. The Policy empowers CSAs with the insight and ability to tune their security programs according to their risks, needs, budgets, and resource constraints while remaining compliant with the baseline level of security set forth in this Policy. The CJIS Security Policy provides a secure framework of laws, standards, and elements of published and vetted policies for accomplishing the mission across the broad spectrum of the criminal justice and noncriminal justice communities. 06/01/2016 i CJISD-ITS-DOC-08140-5.5 CHANGE MANAGEMENT Revision Change Description Created/Changed by Date Approved By Security Policy See Signature 5.0 Policy Rewrite 02/09/2011 Working Group Page Incorporate Calendar APB & Year 2011 APB CJIS ISO Program 5.1 07/13/2012 Compact approved changes and Office Council administrative changes Incorporate Calendar APB & Year 2012 APB CJIS ISO Program 5.2 08/09/2013 Compact approved changes and Office Council administrative changes Incorporate Calendar APB & Year 2013 APB CJIS ISO Program 5.3 08/04/2014 Compact approved changes and Office Council administrative changes Incorporate Calendar APB & Year 2014 APB CJIS ISO Program 5.4 10/06/2015 Compact approved changes and Office Council administrative changes 5.5 Incorporate Calendar CJIS ISO Program 06/01/2016 APB & Year 2015 APB Office Compact approved changes and Council administrative changes 06/01/2016 ii CJISD-ITS-DOC-08140-5.5 SUMMARY OF CHANGES Version 5.5 APB Approved Changes 1. Section 5.2 Policy Area 2: Security Awareness Training: added language, Spring 2015, APB20, SA2, Security Awareness Training Requirements. 2. Section 5.2.1.1 All Personnel: change section title to “Level One Security Awareness Training”, modify language and required training topics, Spring 2015, APB20, SA2, Security Awareness Training Requirements. 3. Section 5.2.1.2 Personnel with Physical and Logical Access: change section title to “Level Two Security Awareness Training”, modify language and moved required training topics from previous Section 5.2.1.1, Spring 2015, APB20, SA2, Security Awareness Training Requirements. 4. Section 5.2.1.3 Personnel with Information Technology Roles: change section title to “Level Three Security Awareness Training”, modify language and moved required training topics from previous Section 5.2.1.2, Spring 2015, APB20, SA2, Security Awareness Training Requirements. 5. Section 5.2.1.4 Level Four Security Awareness Training: added section and moved required training topics from previous Section 5.2.1.3, Spring 2015, APB20, SA2, Security Awareness Training Requirements. 6. Section 5.2 Figure 4: changed figure title and added a use case for each level of security awareness training, Fall 2015, APB12, SA4, Security Awareness Training Requirements. 7. Section 5.3 Incident Response: modified language to indicate any incident involving criminal justice information, Fall 2015, APB12, SA3, Security Incident Response Reporting. 8. Section 5.6.2.2 Advanced Authentication: add language describing the use of out-of-band authenticator, Spring 2015, APB 20, SA4, Clarification of Out-of-Band Authentication for Advanced Authentication (AA). 9. Section 5.9.1 Physically Secure Location: modified language to include security awareness training reference, Spring 2015, APB20, SA2, Security Awareness Training Requirements. 10. Section 5.10.2 Facsimile Transmission of CJI: modified language and introduced a new requirement, Fall 2015, APB12, SA1, Faxing Requirements in the CJIS Security Policy. 11. Section 5.11.2 Audits by the CSA: add language allowing CSA audits of vendor facilities, Spring 2015, APB 20, SA3, CJIS Systems Agency (CSA) Audit of Contractor Facilities. 12. Section 5.12.1.1(7) Minimum Screening Requirements for Individuals Requiring Access to CJI: add language allowing CSO delegation of continuing access determination for non-felony offenses, Spring 2015, APB 20, SA5, CJIS Systems Officer (CSO) Delegation of Personnel Screening Requirements. 13. Section 5.13 Policy Area 13: Mobile Devices: modify language throughout the entire section based on Mobile Security Task Force recommendations, Fall 2015, APB12, SA2, Request to Modify CJIS Security Policy Section 5.13 Mobile Devices. 14. Appendix A Terms and Definitions: add definitions for “Out-of-band” and “In-band”, Spring 2015, APB 20, SA4, Clarification of Out-of-Band Authentication for Advanced Authentication (AA). 06/01/2016 iii CJISD-ITS-DOC-08140-5.5 15. Appendix A Terms and Definitions: add definition for “Facsimile (Fax)”, Fall 2015, APB12, SA1, Faxing Requirements in the CJIS Security Policy. 16. Appendix A Terms and Definitions: add definitions for “Full-feature Operating System”, “Limited-feature Operating System”, “Mobile (WiFi) Hotspot”, “Wireless Access Point”, and “Wireless (WiFi) Hotspot”, Fall 2015, APB12, SA2, Request to Modify CJIS Security Policy Section 5.13 Mobile Devices. 17. Appendix F.1 Security Incident Response Form: modified form to indicate any incident involving criminal justice information, Fall 2015, APB12, SA3, Security Incident Response Reporting. 18. Appendix K Criminal Justice Agency Supplemental Guidance: replace current appendix with new appendix, Spring 2015, APB 20, SA8, Evaluation of Appendix K. Administrative Changes1 1. Figure 14 – A Local Police Department’s Information Systems & Communications Protections: change the title of the figure and add use faxing cases. Security and Access Subcommittee requested the use cases be added. 2. Appendix C Network Topology Diagrams, Figures C.1-A, B, C, and D: added required information from Section 5.7.1.2 Network Diagram to diagrams. Sample diagrams did not contain the required elements of agency name, effective date of drawing, and “For Official Use Only” marking. 3. Appendix G Best Practices: added new Appendix G.5 Administrator Accounts for Least Privilege and Separation of Duties, Spring 2015, SA6 (info only). Security and Access Subcommittee approved the appendix to be added under the APB approved ISO latitude for administrative changes. KEY TO APB APPROVED CHANGES (e.g. “Fall 2013, APB11, SA6, Future CSP for Mobile Devices”): Fall 2013 – Advisory Policy Board cycle and year APB## – Advisory Policy