Companion to: Getting ready for a CJIS technical security audit

CJIS audit evidence checklist

What to have in your evidence folder before the auditor asks. Print it, or save it as a PDF from your browser's print menu.

Agency
Audit date
Prepared by

Scope and network

  • Confirmed with the CSA which CJIS Security Policy version this audit uses (name, date)
  • List of every workstation, server, and mobile device that can access, store, or process CJI
  • Dated network diagram showing CJI systems, the boundary firewall, and the path to the state network
  • Device inventory: hostname, OS version, role, and location
  • Boundary firewall rules exported, with a note on the purpose of each rule
  • How CJI is encrypted in transit, with the FIPS validation for each encryption module
  • Wireless networks that touch CJI systems, and how they are secured

Accounts and authentication

  • Current list of users with CJI access, each account unique to one person
  • Proof MFA is enforced for every CJI login: Windows, apps, VPN, remote support, admin accounts
  • Password or authenticator policy as configured (screenshot or export)
  • Procedure for disabling accounts when someone leaves, with a recent example
  • List of administrative accounts and who holds them
  • Break-glass account documented, with how its credentials are protected

Maintenance and monitoring

  • Patch status for every in-scope system
  • Antivirus or EDR status for every in-scope device
  • What is logged, where logs are kept, and for how long
  • Backups of CJI systems, including whether backups are encrypted
  • Any unsupported operating systems or software, with a replacement plan

People and paperwork

  • Fingerprint-based background checks for everyone with unescorted access, including contractors
  • Signed CJIS Security Addendum certifications for contractor staff
  • Security awareness training records by person and date
  • Written security policies, dated and approved
  • Incident response plan, with contact information that is current
  • Physical security: who has keys or badge access to areas with CJI

After the audit

  • Each finding logged with an owner, target date, and planned evidence
  • Evidence folder kept current between audits (reviewed quarterly)

This checklist is a starting point, not legal or compliance advice. Your state CJIS Systems Agency's requirements always take priority. Current policy documents are published at theFBI CJIS Security Policy Resource Center.

From Small Town Sysadmin. Free to print and share.