FBI CJIS Security Policy v6.1 Raises Encryption Strength and Vulnerability Scan Frequency
What Happened – The FBI released CJIS Security Policy version 6.1 on June 25 2026. The update tightens cryptographic requirements (minimum 256‑bit keys for data in transit and at rest) and increases the mandated vulnerability‑scanning cadence from quarterly to monthly. It also clarifies audit‑priority phases, keeping Priority 1 controls sanctionable now while lower‑priority controls remain in “zero‑cycle” until Sept 2027.
Why It Matters for Trust & Control Assurance –
- Continuous control‑assurance programs must already capture evidence of encryption strength and monthly vulnerability scans to stay ahead of the new baseline.
- Mapping the CJIS controls to the Verisq Common Framework (VCF) provides a single audit artifact that satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).
- The Trust Center can automate collection of encryption‑configuration logs and scan‑report attestations, giving a defensible audit trail before the next sanction cycle.
Who Is Affected – Law‑enforcement agencies, state CJIS System Administrators, and any contractors handling Criminal Justice Information (CJI).
Recommended Actions –
- Update encryption policies to require 256‑bit symmetric keys for all CJI in transit and at rest.
- Shift vulnerability‑management schedules to monthly scans and retain the reports as audit evidence.
- Verify your current audit phase with the relevant State CJIS System Agency and begin collecting continuous evidence in the Trust Center. Source: BleepingComputer
Technical Notes – The policy change does not introduce a new CVE; it amends existing control requirements (SC‑13, SC‑28) and the vulnerability‑management frequency. No new software or hardware is mandated, but organizations must ensure their cryptographic modules support 256‑bit keys and that scanning tools can run on a monthly cadence. Source: same as above