

CJIS Controls and Compliance Training
Your People Are Either Your Strongest Control or Your Biggest Liability — Training Is What Makes the Difference.
Technical controls and documentation mean nothing if the people responsible for operating them don't understand what the FBI CJIS Security Policy requires, why it requires it, and exactly what their role is in maintaining it. CJIS compliance is not an IT problem. It is an organizational problem — and training is how you solve it at the human level.
WHO THIS SERVICE IS FOR
Criminal Justice Agencies (CJA), Noncriminal Justice Agencies (NCJA), Interface Agencies (IA), vendors, and any organization that processes, stores, or transmits Criminal Justice Information.
THE PROBLEM YOU'RE FACING
Most CJIS compliance training falls into one of two categories — a once-a-year awareness video that nobody remembers, or a dense policy recitation that leaves practitioners no clearer on what they are actually supposed to do. Neither produces compliant behavior. Neither builds operational confidence. And neither holds up when an auditor asks your staff how they handle a specific control requirement and gets a blank stare in return.
The FBI CJIS Security Policy places explicit training obligations on agencies and vendors — Security Awareness Training is a mandatory control requirement, not an optional best practice. But mandatory completion is not the same as operational understanding. The goal of training is not a signed acknowledgment form. The goal is a staff that knows what CJI is, who is authorized to access it, what the controls around it require, and what to do when something goes wrong. Effective CJIS training should create confident, informed personnel who understand both the technical and operational responsibilities tied to protecting Criminal Justice Information every day.
Sound Familiar?
Lack of Operational Understanding: Your staff can confirm they completed annual security awareness training but cannot explain what Advanced Authentication requires or why it applies to them
Unclear Technical Control Requirements: Your IT team manages CJIS-relevant systems without a clear understanding of the specific Policy controls those systems are required to implement
Inconsistent Personnel Onboarding: New personnel are onboarded without structured CJIS-specific orientation — they learn compliance informally, inconsistently, and incompletely
Untrained CJIS Systems Officer Responsibilities: Your CJIS Systems Officer is executing compliance responsibilities without formal training on what the Policy actually requires of that role
No Training Effectiveness Validation: Training completion is tracked but training effectiveness has never been assessed
OUR METHODOLOGY
The CJIS Academy Controls and Compliance Training engagement delivers control-by-control, operationally focused instruction built around what each requirement actually means, how it applies in practice, and what auditors look for when they assess it. Training is not a lecture — it is a working session that leaves every participant with a clear, role-specific understanding of their CJIS compliance obligations.

PHASE 1:
Audience Assessment & Training Scope
Every organization has a different training need. We begin by identifying every role that carries CJIS compliance responsibility — IT staff, security teams, compliance officers, CJIS Systems Officers, agency administrators, and vendor personnel — and scoping training content to the specific Policy requirements each role is responsible for implementing and maintaining.

PHASE 2:
Control-by-Control Instruction
Training is delivered across every applicable FBI CJIS Security Policy control family — not as a policy summary, but as operational instruction. Each control is explained in plain language, applied to real-world scenarios your staff actually encounters, and connected to the specific audit evidence that control requires. Participants leave knowing not just what the control says but what it looks like in practice.

PHASE 3:
Role-Specific Application
General awareness is not enough. Each role receives instruction tailored to their specific responsibilities — IT staff on technical control implementation and configuration requirements, compliance officers on documentation and evidence management, CJIS Systems Officers on program oversight and audit preparation, and executive leadership on governance obligations and risk posture.

PHASE 4:
Knowledge Assessment & Completion Documentation
Training effectiveness is assessed through structured knowledge checks that verify comprehension, not just attendance. Every participant receives a completion certificate. Training records are documented in a format that satisfies the FBI CJIS Security Policy's Security Awareness Training requirements and is ready for auditor review.

CJIS training that only gets you to a signed acknowledgment form isn't training — it's paperwork. The standard I hold every training engagement to is simple: when an auditor asks your staff a direct question about a control requirement, they should be able to answer it with confidence.
— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

CJIS Controls AND Compliance Training
PACKAGE
Every Training Engagement Produces a Complete, Audit-Ready Training Package.

All documents are delivered in editable format, formatted for professional presentation, and built to be maintained by your team without ongoing outside support.
WHAT YOU RECEIVE
Custom Training Curriculum: Role-specific training content mapped to every applicable FBI CJIS Security Policy control family and tailored to your organization's environment and operational context
Instructor-Led Training Sessions: Live, interactive instruction delivered to each audience group with real-world scenarios, Q&A, and direct policy application
Training Materials Package: Participant workbooks, reference guides, and control summary cards that serve as ongoing operational references after training concludes
Knowledge Assessment Results: Documented comprehension results for every participant, identifying any areas requiring reinforcement
Completion Certificates: Individual certificates for every trained staff member, formatted for personnel file inclusion
Training Records Register: A complete, auditor-ready training log documenting every participant, session date, content covered, and completion status
CJIS Systems Officer Orientation Package: Dedicated supplemental materials for the individual responsible for owning and operating your CJIS compliance program
WHY THIS ENGAGEMENT PAYS FOR ITSELF
Trained Staff are Compliant Staff — and Compliant Staff are the Most Cost-Effective Control in Your Entire CJIS Program.

Satisfy Mandatory Training Requirements
Security Awareness Training is an explicit FBI CJIS Security Policy obligation, and documented, role-specific instruction eliminates a standing audit finding risk while strengthening overall compliance readiness

Protect Your CJIS Systems Officer
Equip the person responsible for managing your compliance program with the knowledge, tools, and operational understanding needed to effectively run and maintain it

Reduce Human Error Violations
Most CJI handling violations originate from staff who do not fully understand the rules, responsibilities, or control requirements tied to handling Criminal Justice Information properly

Strengthen Audit Posture & Compliance Culture
Auditors interview staff directly, and trained personnel provide confident, accurate answers while organizations that understand why controls exist maintain compliance more consistently over time
Frequently Asked Questions
Do you need access to CJI to deliver training?
No. CJIS Academy does not require access to Criminal Justice Information at any point during a training engagement. All instruction is delivered against Policy requirements and your operational environment — not against the data itself. In rare instances where accessing CJI is necessary for sensitive consultative engagements, we will oblige and execute the required CJIS Security Addendum documentation to authorize such access in full compliance with FBI CJIS Security Policy requirements.
Is this training suitable for non-technical staff?
Yes. Training is scoped and delivered by audience — non-technical staff receive instruction focused on their specific compliance obligations, in plain language that does not assume IT or security expertise. Technical staff receive deeper instruction on control implementation and configuration requirements. Everyone gets what applies to them.
How is training delivered — in person or virtually?
Both. Training is available as instructor-led in-person sessions, live virtual sessions, or a combination of both depending on your organization's size, geography, and operational requirements. Delivery format is determined during scoping.
How long does a training engagement take?
Most training engagements are delivered over one to three days of instruction, depending on the number of audience groups, the breadth of control families covered, and your organization's scheduling requirements. We work around shift schedules and operational constraints to minimize disruption.
Does this satisfy the FBI CJIS Security Policy's Security Awareness Training requirement?
Yes. Training content, delivery, knowledge assessment, and completion documentation are all designed to satisfy the Security Awareness Training control requirement under the FBI CJIS Security Policy. Every training record produced is formatted for direct audit submission.
Can training be customized for a specific incident, finding, or control area?
Yes. Organizations that have received audit findings related to specific control areas, or that have experienced a CJI handling incident, can engage CJIS Academy for targeted training focused on the specific requirements at issue — without committing to a full curriculum engagement.


