

CJI System Security Plans (SSPs) and Control Matrices
The Two Documents Every Serious Law Enforcement Client — and Every Cloud Platform — Will 100% Eventually Ask You For.
You can have strong technical controls, a signed CJIS Security Addendum, and a clean security record — and still be unable to answer the single most important question a law enforcement client, a procurement officer, or a cloud platform will ask: "Where is your System Security Plan?"
WHO THIS SERVICE IS FOR
Cloud and hosting providers, managed service providers, SaaS companies and software developers, criminal justice technology vendors (CAD, RMS, JMS, body camera, biometric), data center operators, and any private sector organization that operates a system processing, storing, or transmitting Criminal Justice Information and must document its security posture and define its control boundary.
THE PROBLEM YOU'RE FACING
The SSP is the authoritative document that describes your CJI system, its boundary, and exactly how every applicable control is met. The control matrix is what resolves the question nobody else can answer for you — who is actually responsible for each control. Without both, your compliance posture exists in pieces. With them, it exists as a single, defensible system of record.
Most vendors have compliance documentation scattered across policies, procedures, vendor questionnaires, and email threads — but no single authoritative document that ties it all together control by control. Worse, vendors operating in the cloud cannot clearly articulate which controls they own, which they inherit from the platform, and which are shared with the agency. When a law enforcement client, a cloud provider, or an auditor asks for a System Security Plan and a control responsibility matrix, the vendor either has nothing to provide or hands over a generic document that does not map to the FBI CJIS Security Policy at the depth required.
Sound Familiar?
Missing System Security Plan: A law enforcement client, cloud platform, or auditor has asked for your System Security Plan and you do not have one
Unclear Cloud Control Ownership: You operate in AWS GovCloud, Azure Government, or Microsoft GCC and cannot clearly state which controls you inherit from the platform versus which your organization owns
Fragmented Compliance Documentation: Your compliance documentation exists in scattered pieces, but no single document describes your system and its controls in one authoritative place
Undefined Control Responsibilities: You cannot produce a control responsibility matrix showing what your organization is accountable for versus the cloud provider versus the agency
Undocumented Control Implementations: A procurement officer or auditor asked how a specific control is implemented and you could not point to a documented implementation statement

A compliance program is only as defensible as its ability to explain how controls are implemented and who is responsible for them. The System Security Plan and Control Responsibility Matrix provide the authoritative foundation that turns compliance from a collection of documents into a clearly defined, auditable system of record.
OUR METHODOLOGY
Our Process Is Designed to Define Your System, Document Every Applicable Control, and Establish Clear Responsibility Boundaries—Creating the Foundational Compliance Artifacts Clients, Auditors, and Cloud Platforms Expect to See.

PHASE 1:
System Definition & Authorization Boundary Scoping
Your CJI system is formally defined — components, interconnections, data flows, hosting environment, and the precise authorization boundary within which Criminal Justice Information lives. Most vendors have never drawn this boundary explicitly, and it is impossible to document controls accurately until it exists.

PHASE 2:
Control Implementation Documentation
Every control applicable to your role across all 18 FBI CJIS Security Policy control families is documented with a specific implementation statement — what the control requires, how your organization satisfies it, who is responsible, and what evidence demonstrates it. Not a checkbox. A narrative an auditor can verify.

PHASE 3:
Control Responsibility Matrix Development
The shared responsibility question is resolved definitively. Every control is mapped to its true owner — implemented by your organization, inherited from the cloud platform's FedRAMP authorization, or shared with the law enforcement agency. For GovCloud and GCC vendors, control inheritance is mapped explicitly so you can show exactly where the platform's responsibility ends and yours begins.

PHASE 4:
Review & Validation
The completed SSP and control matrix are reviewed against current FBI CJIS Security Policy requirements. Every control is validated for accuracy, and any control not yet satisfied is flagged in an unsatisfied control register so you know precisely where remediation is required before the document goes to a client or auditor.

The System Security Plan is the document everything else points back to. Vendors hand a client a stack of policies and think they've answered the compliance question — but the client wants to know how the system actually works, control by control, and who owns what. The SSP and the control matrix are the only documents that answer that. Especially for cloud and managed service providers, the shared responsibility matrix is where the real exposure hides — and where I find vendors claiming controls the platform actually owns, or assuming the platform covers controls that are squarely theirs.
— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

CJI System Security Plans and Control Matrices PACKAGE
Every CJI System Security Plans and Control Matrices Engagement Produces a Complete, Operationally Deployable Documentation Suite.

All documents are delivered in editable format, formatted for professional presentation, and built to be maintained by your team without ongoing outside support.
WHAT YOU RECEIVE
System Security Plan (SSP): A complete, control-by-control document describing your CJI system, its authorization boundary, and the implementation of every applicable FBI CJIS Security Policy control
Authorization Boundary & Data Flow Documentation: A documented system description with component inventory, interconnections, and the CJI data flows that define your boundary
Control Responsibility Matrix (CRM): A definitive mapping of every applicable control to its owner: implemented, inherited, or shared
Cloud Inheritance Mapping: For GovCloud, Azure Government, and GCC vendors, an explicit mapping of which controls are inherited from the platform's FedRAMP authorization and which remain your responsibility
Control Implementation Statements: A documented narrative for every applicable control describing exactly how it is satisfied and evidenced
Unsatisfied Control Register: A clear record of any control not yet met, flagged and prioritized for remediation before the SSP is presented to a client or auditor
WHY THIS ENGAGEMENT PAYS FOR ITSELF
When a Client, Auditor, Procurement Officer, or Cloud Platform Requests Evidence of Your Compliance Posture, the Ability to Produce a Current SSP and Control Matrix Immediately Demonstrates Maturity, Reduces Scrutiny, and Accelerates Decision-Making.

Produce the Document on Demand
When a client, cloud platform, or auditor asks for your System Security Plan, you hand over a complete, professionally developed document instead of scrambling to assemble one.

Establish an Authoritative System of Record
The SSP becomes the foundation every other compliance document, assessment, and conversation points back to.

Resolve Shared Responsibility Definitively
Eliminate the dangerous ambiguity of assuming the platform covers a control it does not, or claiming a control the platform actually owns.

Accelerate Procurement & Platform Onboarding
Vendors who can produce a current SSP and control matrix move through law enforcement procurement and cloud platform vetting faster than those who cannot.
Frequently Asked Questions
Do we need to be in the cloud for this service to apply?
No. The SSP and control matrix apply to on-premises, hybrid, and cloud-hosted systems alike. For cloud and managed service providers, the control inheritance mapping is an especially critical component — but the core SSP applies to any CJI system regardless of where it is hosted.
We operate in Microsoft GCC / AWS GovCloud / Azure Government. Can you map our control inheritance?
Yes — and this is central to the engagement. We map which controls are inherited from the platform's FedRAMP authorization and which remain your organization's responsibility, so you can show a client or auditor exactly where the platform's responsibility ends and yours begins.
Do you need access to CJI to develop the SSP?
No. All work is conducted against your system architecture, configuration, and documentation — not the data itself. In rare instances where CJI access is necessary, we will execute the required CJIS Security Addendum documentation
How does this relate to the gap assessment?
They are complementary. The gap assessment identifies where your posture falls short; the SSP and control matrix document your posture authoritatively, control by control. Many vendors engage them in sequence — gap assessment first to establish the baseline, then the SSP to formalize and document the resulting posture.
How long does this engagement take?
Four to eight weeks for most vendor engagements, depending on system complexity, the number of interconnections, and whether cloud inheritance mapping is in scope.

