Technology & Security

CJIS Security Policy: Questions to Ask Registry Software Vendors

Ten CJIS Security Policy questions to ask any sex offender registry software vendor, with what a good answer looks like for MFA, encryption, logging, and more.

Justice Compliance Team5 min read
Written for:Agency ITRegistry CoordinatorsCommand Staff
Technology & Security

Justice Compliance Insights

In this article

Registry software holds some of the most sensitive information your agency manages: registrant identities, addresses, employment details, photos, and often data exchanged with state and federal systems. If any of that information is treated as criminal justice information (CJI) in your state, the CJIS Security Policy applies to how it is stored, accessed, and protected.

Vendors know this, and almost every sales deck mentions CJIS. The problem is that a slide is not evidence. This article gives you a set of numbered questions to ask any registry software vendor, along with what a good answer looks like, so your IT staff and command team can separate real controls from marketing language.

Start with the right framing

Before you ask a single question, keep two points in mind.

First, there is no official CJIS certification for software products. The FBI does not certify vendors. If a vendor claims its product holds an official CJIS certification, treat that as a warning sign. A better description is a system built to CJIS Security Policy requirements, with the agency and its state CJIS Systems Agency (CSA) confirming that the deployment meets policy.

Second, compliance is shared. The vendor controls the hosting environment and application security. Your agency controls who gets accounts, how passwords and devices are managed, and whether audit logs are actually reviewed. A strong vendor will explain clearly where its responsibility ends and yours begins.

The questions, and what a good answer looks like

1. How do users authenticate?

The CJIS Security Policy calls for advanced authentication, commonly delivered as multi-factor authentication (MFA), for access to CJI in many situations.

What a good answer looks like: MFA is enforced for every user, not offered as an optional setting. The vendor can describe supported factors (authenticator apps, hardware tokens, or agency single sign-on with MFA) and can show how administrators enforce it across the agency.

2. Is data encrypted in transit and at rest?

Encryption protects data moving across networks and data stored in databases, file storage, and backups.

What a good answer looks like: All connections use current TLS. Data at rest, including backups and stored documents, is encrypted. The vendor names the cryptographic modules it uses and can provide FIPS 140 validation certificate numbers you can verify independently. "We use strong encryption" is not enough.

3. What is logged, and who reviews the logs?

Audit logging is how your agency proves who viewed or changed a record and when.

What a good answer looks like: The system logs logins, failed login attempts, record views, edits, exports, and permission changes, each with a user, timestamp, and source. Logs are protected from alteration. Agency administrators can search and export logs on their own, and the vendor describes how its own staff review system-level logs for suspicious activity. Ask how long logs are retained and confirm that meets your CSA's requirements.

4. Who at the vendor can access our data?

Personnel security applies to anyone with access to unencrypted CJI, including vendor employees and subcontractors.

What a good answer looks like: The vendor limits access to a small, named group of staff. Those people undergo fingerprint-based background checks, complete CJIS security awareness training, and sign the FBI CJIS Security Addendum. The vendor can describe how access is granted, reviewed, and removed when someone changes roles or leaves.

5. Where is our data stored?

What a good answer looks like: All agency data, including backups, disaster recovery copies, and logs, is stored in data centers located in the United States. The vendor states this in the contract, not just in a brochure, and discloses any subcontractors that touch the data.

6. How is access controlled inside the application?

Least privilege means each user sees and does only what their role requires.

What a good answer looks like: The application uses role-based permissions that your administrators control. A records clerk, a field deputy, and a supervisor have different rights. The system supports automatic session timeouts, account lockout after repeated failed logins, and prompt deactivation of departed users.

7. What happens during a security incident?

What a good answer looks like: The vendor has a written incident response plan that it tests. It commits to notifying your agency within a defined time frame after discovering an incident that may affect your data, and explains how it will coordinate with your agency and CSA on reporting. Ask for a summary of the plan and the notification commitment in writing.

8. How are changes, patches, and vulnerabilities managed?

What a good answer looks like: The vendor runs regular vulnerability scanning, applies security patches on a defined schedule, and follows a change management process with testing before production releases. It can describe how it handles critical vulnerabilities that need faster action.

9. Will you sign the CJIS Security Addendum and support a CSA review?

What a good answer looks like: Yes, without hesitation. The vendor has signed addenda with other agencies, understands the paperwork, and will cooperate with audits or questionnaires from your CSA. It can supply documentation such as a security controls summary mapped to CJIS Security Policy areas.

10. How do we get our data back?

What a good answer looks like: The contract states that the agency owns its data. The vendor provides complete exports in a usable format on request and at contract end, and describes how it securely destroys agency data afterward.

A quick evaluation checklist

Use this table to track evidence as you compare vendors.

AreaEvidence to requestReceived?
AuthenticationMFA enforcement description or screenshot of admin setting
EncryptionFIPS 140 validation certificate numbers
Audit loggingSample audit log export and retention statement
Personnel securityDescription of background check and training process
Data locationContract language on U.S.-only storage
Access controlRole and permission matrix
Incident responsePlan summary and notification commitment
Security addendumWillingness to sign and support CSA review
Data returnExport format and destruction process

Your agency's side of the work

Even with a strong vendor, your agency has duties. Plan for these before go-live:

  • Confirm with your CSA which approvals or notifications are required for a new vendor.
  • Assign a local agency security officer or point of contact for the system.
  • Define roles and grant the minimum permissions each user needs.
  • Train every user on security awareness before issuing accounts.
  • Schedule regular audit log reviews and document them.
  • Build a process to disable accounts the same day someone leaves.
  • Check your state statute and agency policy for any additional requirements.

Next steps

Asking these questions early saves time later, because a vendor that cannot answer them clearly is unlikely to pass a CSA review. Share this list with your IT lead and CSA contact, and request written answers from every vendor you evaluate.

Justice Compliance is built to CJIS Security Policy requirements, stores agency data only in the United States, and keeps a complete, time-stamped audit trail of every record change. You can review our approach on the security page, and if you are building a formal evaluation, our registry software RFP checklist covers the rest of the process. When you are ready, request a demo and bring your questions.

Key takeaways

  • No vendor can make your agency compliant on its own; compliance is a shared responsibility
  • Ask for evidence such as validation certificates, sample audit logs, and signed addenda
  • Bring your CJIS Systems Agency into the evaluation early
  • Treat data location, personnel screening, and incident response as contract terms

This article is general guidance based on federal SORNA minimums and common registry practice. It is not legal advice. Always check your state statute and agency policy.

Free PDF guide

The Future of Sex Offender Registry Technology

Emerging trends shaping registry operations over the next decade.

Download free

Keep reading

Related articles

All articles →

See it in practice

See how Justice Compliance supports this work

A personalized walkthrough built around your agency's registry workflows, verification schedule, and reporting needs.