CJIS Security Policy Areas Explained: The Original 13 and the Current 19
A CJIS Security Policy Area is one of the numbered sections in the FBI’s CJIS Security Policy. Each area groups related security rules together, like access control or incident response. The FBI’s current policy text lists 19 of them, in order, in Section 5.
Ask how many Policy Areas the CJIS Security Policy has and you will get two different answers. Both are correct, depending on the source. The FBI’s own text lists 19. Microsoft’s official CJIS compliance documentation still says 13.
Both numbers are right. They are just counting two different points on the same list.
Neither source is wrong. They are describing two stages of the same policy. Microsoft’s 13-area framing reflects the Policy’s structure before a 2020 update. The FBI added six more areas after that, built around NIST security controls. If you have seen both numbers and wondered which one to trust, the answer is: both, once you know what each is measuring. This guide walks through all 19 areas in order, then explains the original 13 in plain language. If you want the broader picture of what CJIS compliance means for your agency or vendor business first, our guide to CJIS compliance covers that ground.
All 19 CJIS Policy Areas, In Order
The table below lists every Policy Area in the order the FBI’s current policy text presents them. The first 13 make up the original set. The last six were added later, aligned to NIST SP 800-53 controls.

Microsoft’s “13 areas” language matches the top 13 rows above word for word. That is not a coincidence. It is the original list, before the six newer areas joined it.
The Original 13 Policy Areas, In Brief

Here is what each of the original 13 areas actually requires, grouped by what they have in common.
Information Sharing, Training, Incident Response, and Auditing
Information Exchange Agreements governs how CJI moves between organizations. Any private contractor doing criminal justice work for an agency needs a signed CJIS Security Addendum. That addendum authorizes their access to Criminal History Record Information. It also holds them to the same training and audit standards as the agency itself.
Awareness and Training sets the baseline for who needs security training and when.
- New staff, including contractor and vendor staff, must complete training within six months of starting.
- Everyone with CJI access must repeat training every two years after that.
- An agency can accept training records from another agency, but it then owns the risk if that training falls short.
Incident Response requires an agency to maintain a real capability for handling security incidents. That means preparing for incidents, detecting them, analyzing them, containing them, and recovering. Incidents get tracked up a chain: local agency, state security officer, then the FBI’s own incident response team. A serious event can pull in the Department of Justice’s incident response staff too.
Auditing and Accountability requires agencies to log and track system activity involving CJI, so there is a record to review if something goes wrong.
Access and Identity
Access Control and Identification and Authentication work together to govern who can reach CJI and how they prove who they are. The headline requirement here is Advanced Authentication: a second factor beyond a username and password. This applies to CJI access from any device, including mobile. Since October 1, 2024, this requirement sits in the sanctionable, audited baseline. That is why MSPs treat multi-factor authentication as mandatory for any client account that touches CJI, not as a nice-to-have.
Configuration, Media, and Physical Security
Three areas cover the physical and technical hygiene side of CJIS:

- Configuration Management governs how systems that touch CJI are set up, patched, and changed over time.
- Media Protection governs how CJI is handled on physical and digital media, including how it gets destroyed when it is no longer needed.
- Physical and Environmental Protection governs who can physically walk into a space where CJI is processed or stored.
These three areas do not carry the eye-catching numbers that encryption or personnel screening do. They still get audited. A vendor with no documented change-management process, or no controlled visitor log for a server room handling CJI, fails these areas regardless of how strong its passwords are.
Communications, Formal Audits, Personnel, and Mobile Devices
Systems and Communications Protection is where encryption lives. That covers something as ordinary as a networked copier faxing a report to another agency. The only exception is CJI moving over a closed, non-networked phone line.

Formal Audits is the enforcement engine behind the whole Policy.
- The FBI CJIS Division’s Audit Unit audits each state CJIS Systems Agency once every three years.
- Each state agency, in turn, audits the local agencies and contractors under it on the same three-year cycle.
- Serious or unresolved noncompliance can lead to sanctions, and in extreme cases, suspension of an agency’s access to FBI CJIS systems. For a police department, that can mean losing the ability to run criminal history checks entirely.
Personnel Security governs who is allowed unescorted access to unencrypted CJI, or to a secure area while CJI is being handled.
- Anyone in that position, employee, contractor, or vendor technician, needs identity verification plus a state and national fingerprint-based background check.
- A felony conviction requires the agency to deny access, with a narrow, case-reviewed exception.
- Misdemeanors are a judgment call for the agency’s CJIS Systems Officer.
- Background re-investigation is recommended every five years, unless the agency uses continuous monitoring instead.
This is why an MSP’s field technicians and remote-access admins need fingerprint-based vetting, not just a badge check, if their job puts unencrypted CJI in front of them.
Mobile Devices extends the same access and authentication rules to phones and tablets. If a device can reach CJI, it needs the same Advanced Authentication the Policy requires everywhere else.
The Six Newer Policy Areas, and Why They Were Added
Starting with the v5.9 modernization in June 2020, the FBI restructured its policy areas to align with NIST SP 800-53, the federal government’s core security-control catalog. Six new areas joined the original 13. Here is what each one covers.
- System and Services Acquisition covers how an agency evaluates and contracts with vendors, including cloud providers, before those vendors ever touch CJI. If you are weighing whether a cloud platform fits this requirement, see our page on whether Microsoft 365, AWS, or Azure meet CJIS standards.
- System and Information Integrity covers malware protection, security alerts, and flaw remediation on systems that process CJI.
- Maintenance covers how systems get serviced and patched without exposing CJI in the process.
- Planning requires agencies to document their security approach in writing, not just practice it informally.
- Contingency Planning covers backup, recovery, and continuity of operations if a system goes down.
- Risk Assessment requires agencies to formally evaluate and document their security risks on an ongoing basis, not just react to incidents after they happen.
These six areas did not replace anything. They sit alongside the original 13, closing gaps around vendor risk, system integrity, and formal risk management that the earlier policy touched only lightly.
Why the Policy Area Count Matters for Compliance
Here is the part that trips up agencies and vendors alike: audits are not conducted against whichever count a vendor’s marketing page happens to use. They are conducted against the FBI’s full current policy text.
That text lists 19 policy areas. A cloud vendor’s compliance page that references “13 areas” is not necessarily out of date. It may simply be describing which of the 19 apply to that vendor’s specific role, since not every area governs every type of organization the same way.
But if you are the one being audited, or the one advising a client who will be, working from a 13-area mental model risks missing real requirements. Risk Assessment, Contingency Planning, and the other newer areas are just as auditable as Access Control or Personnel Security. Our CJIS compliance checklist for IT vendors walks through the full current list, not just the original 13.
What This Means Day to Day for an MSP or IT Vendor
If you support a police department, court, or any agency with CJI access, the policy areas translate into concrete daily work, not abstract categories.

- Multi-factor authentication: every account that can reach CJI needs a second authentication factor, on desktop and mobile alike. – Personnel screening: field technicians, remote-access admins, and anyone else with unescorted access to unencrypted CJI need fingerprint-based background checks, not just a badge check. – Training: staff and contractor personnel need security awareness training within six months of starting, then again every two years. – Documented incident response: a real plan for detecting, containing, and reporting incidents up the chain, not an ad hoc process improvised after the fact.
This is the operational core of LeadingIT’s CJIS compliance IT services: the technical controls the policy actually audits, built and maintained for agencies and the vendors that serve them.
See Where You Stand
Not sure where your agency or vendor business stands against the current 19 areas? Answer a few plain-English questions and see your risk level and gaps in about two minutes, no sign-up required.
Take the free 2-minute CJIS Risk-Check
Related Guides
- What Is CJIS Compliance? A Plain-English Guide
- CJIS Compliance Checklist for IT Vendors
- Is Microsoft 365, AWS, or Azure CJIS Compliant?
Frequently Asked Questions
The FBI’s current policy text lists 19 policy areas in Section 5. Microsoft’s own CJIS compliance documentation references 13 areas, which matches the original set before six newer, NIST-aligned areas were added starting with the 2020 policy update. Both counts are accurate, they just describe different points on the same list.
Advanced Authentication means requiring a second factor beyond a username and password for anyone accessing CJI, including from a mobile device. It became part of the sanctionable, audited baseline as of October 1, 2024. Most MSPs treat this as a mandatory control for any client account that can reach CJI.
Any private contractor performing criminal justice functions for a criminal justice agency, or a government agency with CJI access, needs to be covered by a CJIS Security Addendum. This includes IT vendors, MSPs, and cloud providers whose work brings them into contact with Criminal Justice Information. The addendum authorizes their access and holds them to the same training and audit standards as the agency itself.
The FBI CJIS Division audits each state CJIS Systems Agency once every three years. Each state agency then audits the local agencies and contractors under it on that same three-year cycle. Noncompliance can lead to sanctions, and in serious cases, suspension of an agency’s access to FBI CJIS systems.
Government-tier environments like Office 365 GCC and Azure Government are covered by CJIS Management Agreements Microsoft has signed with most states, which extend fingerprint-based screening to Microsoft’s own operations staff. Regular commercial Microsoft 365 is not automatically covered the same way. No cloud platform is certified CJIS compliant by the FBI, since no such certification exists.
Anyone with unescorted access to unencrypted CJI, whether an employee, contractor, or vendor technician, needs identity verification plus a state-of-residency and national fingerprint-based background check. A felony conviction requires the agency to deny access, with a narrow exception reviewed by the CJIS Systems Officer. Background re-investigation is recommended every five years unless the agency uses continuous monitoring.
Get Your CJIS Controls Right the First Time
Whether you count 13 areas or 19, the requirements are the same, and they get audited against the full current text. LeadingIT builds and maintains the technical controls, encryption, MFA, access logging, and incident response, that CJIS compliance actually runs on for Chicagoland agencies and the vendors serving them.
See our CJIS compliance IT services, or book a call to walk through your specific setup.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
