CJIS Compliance Assessment
Know Where You Stand. Know What to Fix. Be Ready to Demonstrate It.
CJIS compliance involves far more than deploying security products.
Agencies must be able to demonstrate that required administrative, technical and operational security controls are implemented, functioning and supported by appropriate policies, procedures and evidence.
Trestle Networks CJIS Compliance Assessment provides municipal law enforcement agencies with a structured evaluation of their environment against applicable FBI CJIS Security Policy 6.1 requirements.
We combine documentation review, technical validation and hands-on infrastructure experience to identify compliance gaps and turn them into a practical remediation plan.
The result isn't simply another checklist.
It's a prioritized roadmap for improving your CJIS security and compliance posture.
Features
-
Trestle evaluates applicable security requirements against the agency's actual technology, processes and documentation.
Assessment areas can include:
Access Control
Audit and Accountability
Awareness and Training
Assessment, Authorization and Monitoring
Configuration Management
Identification and Authentication
Incident Response
Maintenance
Media Protection
Physical Protection
Planning
Personnel Security
Risk Assessment
System and Services Acquisition
System and Communications Protection
System and Information Integrity
Supply Chain Risk Management
Each applicable requirement is evaluated using available documentation, interviews and technical evidence.
Assessment results identify controls as appropriate to the engagement, such as:
Implemented | Partially Implemented | Not Implemented | Not Applicable | Further Review Required
-
A policy that says a control exists isn't necessarily evidence that the control is operating.
Where appropriate, Trestle validates implementation directly against the agency's technical environment.
Examples include:
User and privileged account controls
Multi-factor authentication
Password and authentication configuration
Remote-access security
Firewall and network segmentation
Encryption
Logging and audit configuration
Security-event monitoring
Endpoint protection
Vulnerability management
Patch and flaw remediation
Configuration management
System inventories
Backup and recovery controls
Administrative access
Network-device security
Wireless infrastructure
Virtualization and cloud infrastructure
This bridges the gap between written policy and operational reality.
-
CJIS compliance requires more than technical controls.
Trestle reviews available policies, procedures and operational evidence to determine whether the agency can demonstrate that required security activities are actually occurring.
Evidence may include:
Security policies and procedures
System inventories
Network diagrams
User and privileged account records
Training records
Vulnerability scan results
Patch-management records
Security logs
Incident-response procedures
Configuration records
Risk assessments
Access agreements
Vendor documentation
Security Addenda
Plans of Action and Milestones
Previous CJIS audit findings
Missing or incomplete documentation is identified as part of the assessment.
-
Not every compliance gap presents the same risk.
Trestle translates assessment findings into an actionable remediation roadmap based on factors including:
CJIS Requirement + Security Risk + Operational Impact + Remediation Priority
This helps agency leadership understand what should be addressed first rather than confronting an undifferentiated list of hundreds of controls.
Findings can be organized into:
Critical Priorities
Issues presenting significant security or CJIS compliance exposure.Near-Term Remediation
Controls requiring corrective action or additional evidence.Program Improvements
Longer-term improvements to security processes, documentation and governance.Validated Controls
Controls for which implementation and supporting evidence were successfully demonstrated. -
Every CJIS Compliance Assessment produces documented, reusable results.
Executive Assessment Report
A management-level overview of the agency's CJIS security and compliance posture, significant findings, risk areas and recommended priorities.
CJIS 6.1 Control Matrix
A detailed control-by-control workbook documenting:
Applicable CJIS requirement
Assessment status
Existing implementation
Evidence reviewed
Identified gap
Recommended remediation
Responsible party
Priority
Remediation status
Remediation Roadmap
A prioritized plan translating assessment findings into actionable technical, administrative and policy tasks.
Evidence Inventory
Documentation of available evidence supporting assessed CJIS controls and identification of evidence that remains missing.
Assessment Review
Trestle reviews findings with agency stakeholders and helps establish practical next steps for remediation.