

Remediation Planning & Implementation
Knowing Your Gaps Is Only Half the Battle — Closing Them is What Protects You.
A gap assessment tells you where you stand. Remediation planning & implementation is where the real work begins — systematically closing every gap, across every control family, with the documentation and evidence needed to prove it.
WHO THIS SERVICE IS FOR
Criminal Justice Agencies (CJA), Noncriminal Justice Agencies (NCJA), Interface Agencies (IA), vendors, and any organization that processes, stores, or transmits Criminal Justice Information.
THE PROBLEM YOU'RE FACING
Most organizations that identify CJIS compliance gaps face the same challenge: they have a findings report but no clear path to resolution. Remediation is not simply a matter of checking boxes — it requires coordinated action across technical configurations, network architecture, operational processes, personnel controls, and documentation buildout.
Without a structured approach, gaps get partially addressed, evidence goes uncaptured, and the next audit finds the same problems the last one did.
Most organizations know they have compliance gaps — the challenge is knowing how to fully close them. Without a structured remediation strategy, gaps often remain partially resolved, poorly documented, and vulnerable to repeat audit findings.
Sound Familiar?
Unresolved Findings: You completed a gap assessment — internally or with another firm — but the findings never got fully resolved
Lack of CJIS-Specific Expertise: Your IT team is capable but doesn't have the CJIS-specific expertise to know what "fixed" actually looks like under Policy requirements
Inconsistent Remediation Efforts: Some control families have been addressed while others remain untouched
Growing Audit Pressure: You have an audit deadline approaching and an unresolved findings list that keeps growing
Documentation Gaps: Your documentation doesn't reflect your actual security posture — and you know it
OUR METHODOLOGY
The CJIS Academy Remediation Planning and Implementation engagement is a project-managed, evidence-driven process that takes every finding from identification to closure — across every dimension the FBI CJIS Security Policy requires.

PHASE 1:
Findings Intake & Remediation Scoping
We begin with a structured review of all gap assessment findings — whether produced by CJIS Academy or a prior assessment. Every finding is categorized by control family, severity, root cause, and remediation type. A full remediation scope is established with realistic timelines, resource requirements, and dependencies mapped before a single action is taken.

PHASE 3:
Process & Operational Remediation
Technical controls alone do not constitute compliance. Every operational gap — undocumented processes, uncontrolled access workflows, missing approval chains, untracked vendor relationships — is addressed through process redesign and operational procedure development built to survive audit scrutiny.

PHASE 5:
Documentation Buildout
Every remediation action is documented with the evidence an auditor will require — configuration screenshots, signed acknowledgments, training completion records, access authorization logs, and policy artifacts. Remediation without documentation is remediation that didn't happen as far as an auditor is concerned.

PHASE 2:
Technical Remediation
We address every technical gap across network architecture, system configuration, access control, encryption, audit logging, advanced authentication, and mobile device management. Technical fixes are implemented to Policy specification — not approximation — with configuration evidence captured at each step.

PHASE 4:
Personnel Controls Remediation
Background screening gaps, lapsed security awareness training, unauthorized access, and need-to-know violations are resolved through direct coordination with agency personnel, HR, and vendor contacts. Access is reauthorized, terminated, or scoped appropriately based on Policy requirements.

PHASE 6:
Closure Verification & Audit Readiness Confirmation
Before the engagement closes, every finding is independently verified as resolved. A closure report is produced documenting the before and after state of each gap, with evidence packages organized and ready for CSA audit submission. This verification process ensures every remediation action aligns with FBI CJIS Security Policy requirements and withstands audit scrutiny.

Remediating CJIS gaps isn't just about fixing what's broken — it's about proving it's fixed in a way that holds up under audit. Evidence isn't an afterthought in this process. It's built in from the first day.
— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

REMEDIATION PLANNING & IMPLEMENTATION PACKAGE
Every Remediation Engagement Produces a Complete, Audit-Ready Evidence Package.

All deliverables are formatted and evidenced in the manner that state CSA auditors and CJIS Systems Officers expect to see.
WHAT YOU RECEIVE
Remediation Project Plan: A fully scoped, sequenced action plan with timelines, ownership assignments, and dependency mapping
Technical Remediation Evidence Package: Configuration documentation, system screenshots, and technical validation for every technical finding closed
Updated Policies & Procedures: Revised or newly developed operational documentation reflecting your remediated compliance posture
Personnel Controls Documentation: Background screening records, training completion logs, access authorization artifacts, and need-to-know justifications
Vendor Remediation Tracking: Documented evidence of vendor gap closure, updated CSA inventory, and revised contractual language where required
Closure Report: A finding-by-finding accounting of every gap, the remediation action taken, and the evidence supporting closure
Audit-Ready Evidence Binder: A complete, organized package built for CSA audit submission
WHY THIS ENGAGEMENT PAYS FOR ITSELF
Remediation is not an Expense — It is the Difference Between Passing an Audit and Failing One.

Close Findings Permanently
Structured, evidence-backed remediation eliminates repeat findings that damage agency credibility and trigger escalating scrutiny.

Reduce Legal & Audit Exposure
Documented remediation creates a defensible record that protects leadership during incidents, breaches, and CSA audits.

Protect CJI Access
Unresolved gaps place your agency’s or vendor’s ability to access, process, store, or transmit Criminal Justice Information at direct risk

Preserve Law Enforcement Contracts
Vendors that remediate quickly and completely protect the client relationships and law enforcement partnerships that define their business.
Frequently Asked Questions
Do you need access to CJI to conduct the remediation engagement?
No. CJIS Academy does not require access to Criminal Justice Information during a standard remediation engagement. All work is conducted against the infrastructure, systems, processes, and documentation that store, process, or transmit CJI — not the data itself. In rare instances where accessing CJI is necessary for sensitive consultative engagements, we will oblige and execute the required CJIS Security Addendum documentation to authorize such access in full compliance with FBI CJIS Security Policy requirements.
Can you remediate findings from a gap assessment conducted by another firm?
Yes. We regularly engage organizations that have prior assessment findings — from internal reviews, state CSA audits, or third-party assessments — that were never fully resolved. We intake those findings, scope the remediation, and execute against them with the same rigor as findings we identified ourselves.
How long does a remediation engagement take?
Timeline depends directly on the number, severity, and complexity of findings. Focused remediations addressing a defined set of technical or operational gaps can be completed in four to six weeks. Comprehensive remediations spanning multiple control families across large or complex environments may run three to six months. A realistic timeline is established during scoping before the engagement begins.
What do you need from our team?
Active collaboration from your IT director, CJIS Systems Officer, and relevant operational staff throughout the engagement. Remediation is not something we do to your organization — it requires your team's participation at key stages, particularly for personnel controls, vendor coordination, and policy review and approval.
How do we know remediation is actually complete?
Every finding goes through independent closure verification before the engagement closes. We do not self-certify remediation — each gap is verified against the specific Policy requirement it violated, with evidence reviewed for sufficiency before it is marked closed.
What happens after remediation is complete?
You receive a complete closure report and audit-ready evidence binder. From there, CJIS Academy can support ongoing program management, audit preparation, training, and documentation currency — or you can maintain the program internally. There is no obligation to continue beyond the remediation engagement.


