The CJIS Security Policy is one of the strictest frameworks a small IT team will ever meet, and its authentication requirements have tightened: multi-factor / advanced authentication is now required for access to Criminal Justice Information (CJI). For county agencies, courts, and the vendors that serve them, "we'll get to it" is no longer a defensible position.
What the policy is really asking
Advanced authentication means more than a password — a second factor that's resistant to replay and phishing, applied to anyone who can reach CJI, from any location. The spirit is simple: a stolen password shouldn't be enough to reach criminal-justice data.
The practical checklist
- Inventory the access paths to CJI — the records system, the mobile data terminals, remote access, and any integration that pulls the data.
- Apply MFA to every one of them, not just the obvious login. The forgotten VPN or vendor portal is where audits fail.
- Cover privileged accounts — the admins who manage those systems are the highest-value target.
- Document it. The auditor wants evidence the control operates, not a promise that it exists.
Budget reality
Underfunded agencies can meet this without a rip-and-replace: modern identity platforms bundle phishing-resistant MFA, and cooperative purchasing vehicles make it affordable. The mistake is scoping too narrowly and leaving one path uncovered. When one door is open, the whole control fails.


