Interestana
Home/News/FBI CJIS v6.1 Enhances Encryption and Scanning
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

FBI CJIS v6.1 Enhances Encryption and Scanning

The Federal Bureau of Investigation (FBI) has released version 6.1 of its Criminal Justice Information Services (CJIS) Security Policy, introducing significant updates aimed at bolstering the security of sensitive criminal justice data. This latest iteration, CJIS v6.1, places a greater emphasis on robust encryption methods and mandates more frequent and thorough vulnerability scanning across systems that handle CJIS data. The policy continues the ongoing transition from periodic security checks to a more continuous model of security assessment, requiring agencies to maintain a constant state of vigilance and adapt to evolving threats.

Specops, a cybersecurity solutions provider, has detailed the key changes within CJIS v6.1 and outlined how government agencies can effectively prepare for upcoming audits. The updated policy introduces more stringent requirements for password management, multi-factor authentication (MFA), and overall identity management. These enhancements are designed to mitigate risks associated with unauthorized access and data breaches, ensuring that only authorized personnel can access critical information. The shift towards continuous assessment means that organizations can no longer rely on annual or bi-annual audits alone; instead, they must implement ongoing monitoring and evaluation processes to identify and address security weaknesses in near real-time.

Key areas of focus in CJIS v6.1 include the strengthening of encryption standards for data both at rest and in transit, ensuring that even if data is intercepted, it remains unreadable without proper decryption keys. The policy also elevates the importance of vulnerability scanning, requiring more frequent and comprehensive scans to identify and remediate security flaws before they can be exploited by malicious actors. This proactive approach is crucial in the current threat landscape, where cyberattacks are becoming increasingly sophisticated and frequent. Agencies are advised to review their current security protocols and invest in solutions that can support these enhanced requirements to ensure compliance and protect sensitive information.

The implications of CJIS v6.1 extend to all entities that access, store, or transmit CJIS data, including law enforcement agencies, courts, and other criminal justice organizations. Preparing for audits under the new policy will necessitate a thorough review of access controls, authentication mechanisms, and data protection measures. Specops suggests that implementing advanced identity and access management solutions, coupled with robust MFA capabilities, will be critical for meeting the policy's updated requirements. The continuous assessment framework also implies a need for integrated security monitoring tools that can provide real-time visibility into the security posture of the agency's IT infrastructure. By addressing these changes proactively, agencies can enhance their security resilience and maintain compliance with federal mandates.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next