

Incident Response Planning & Tabletop Exercises
When It Comes to CJIS Compliance, Knowing the Policy and Proving You Can Execute It Are Two Very Different Things.
A documented incident response plan and a tested, operational compliance posture are not the same thing. The FBI CJIS Security Policy demands both — and auditors are increasingly focused on whether your organization can demonstrate real-world execution, not just policy awareness.
WHO THIS SERVICE IS FOR
Criminal Justice Agencies (CJA), Noncriminal Justice Agencies (NCJA), Interface Agencies (IA), vendors, and any organization that processes, stores, or transmits Criminal Justice Information.
THE PROBLEM YOU'RE FACING
Most organizations have a generic incident response plan — borrowed from a template or inherited from an IT department that has never thought specifically about CJI breach notification requirements. When an actual CJI incident occurs, that plan fails at the moment it is needed most.
The deeper problem is that most organizations have never stress-tested their compliance posture against the actual control requirements of the FBI CJIS Security Policy. Staff have attended training and signed acknowledgment forms — but when placed in a realistic scenario requiring them to apply specific control knowledge, gaps surface immediately.
Tabletop exercises exist to find those gaps before an auditor does. They are not exclusively breach simulations — they are structured, scenario-driven compliance validation tools that test your team's working knowledge of FBI CJIS Security Policy controls across every applicable area.
Sound Familiar?
Non-Compliant Incident Response Planning: Your incident response plan was not written with FBI CJIS Security Policy breach notification requirements in mind
Untested Staff Response Capabilities: Your staff has completed training but has never been tested on applying specific control requirements in practice
No CJIS-Specific Tabletop Exercises: Your organization has never conducted a tabletop exercise scoped to FBI CJIS Security Policy control requirements
Undefined Breach Notification Procedures: Your breach notification timelines, reporting chains, and escalation procedures are undefined or out of date
Unvalidated Policy Knowledge: Your CJIS Systems Officer and IT staff know the Policy exists but have never had their working knowledge formally validated
Unresolved Incident Response Findings: A prior audit cited incident response deficiencies that were acknowledged but never fully addressed
OUR METHODOLOGY
The CJIS Academy Incident Response Planning and Tabletop Exercise engagement builds a CJIS-specific incident response capability and validates your team's operational compliance knowledge through structured, scenario-driven exercises built directly against FBI CJIS Security Policy control requirements.

PHASE 1:
Current State Assessment
Existing incident response documentation, breach notification procedures, and escalation protocols are assessed directly against FBI CJIS Security Policy requirements. Gaps are identified and scoped for development.

PHASE 2:
CJIS-Specific IR Plan Development
A purpose-built CJIS incident response plan is developed covering CJI incident detection and classification, containment procedures, mandatory breach notification timelines, communication protocols, evidence preservation, and post-incident review — built to Policy specification, not adapted from a generic template.

PHASE 3:
Tabletop Exercise Design
Scenarios are designed and scoped to your specific environment — your systems, vendors, personnel, and applicable FBI CJIS Security Policy control obligations. Exercises test working knowledge across multiple control families — access control, personnel security, audit logging, vendor obligations, mobile device controls, and breach notification. Every scenario is built to surface real gaps, not produce comfortable results.

PHASE 4:
Facilitated Tabletop Exercise
The exercise is facilitated with your full compliance team — IT, security, your CJIS Systems Officer, legal counsel, and executive leadership. Participants work through scenarios in real time, applying specific FBI CJIS Security Policy control requirements to realistic situations. Knowledge gaps, role confusion, and procedural breakdowns are captured as they occur.

PHASE 5:
After-Action Report & Plan Remediation
Every finding is documented — knowledge gaps, procedural breakdowns, notification timelines missed, control requirements misapplied. The IR plan and relevant operational procedures are revised to address every finding before the engagement closes.

Tabletop exercises are the most honest assessment of a CJIS compliance program's operational maturity available. It's one thing to have a policy document — it's another thing entirely to put your team in a realistic scenario and find out whether they actually know what the FBI CJIS Security Policy requires them to do.
— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

Incident Response Planning & Tabletop Exercises PACKAGE
Every incident response planning and tabletop exercise engagement produces a complete, audit-ready deliverable package.

All documents are delivered in editable format, formatted for professional presentation, and built to be maintained by your team without ongoing outside support.
WHAT YOU RECEIVE
CJIS Incident Response Plan: Purpose-built to FBI CJIS Security Policy specification, covering breach notification timelines, mandatory reporting obligations, containment procedures, and post-incident review protocols
Breach Notification Procedures: Documented timelines, reporting chains, and escalation procedures for every required notification party
Tabletop Exercise Scenario Package: Full scenario design, inject sequence, and facilitator guide, available for reuse in future internal exercises
After-Action Report: Formal documentation of every gap, knowledge deficiency, and procedural breakdown identified, with remediation mapped to specific Policy control requirements
Revised & Validated IR Plan: Updated to address every after-action finding, producing a tested document rather than a theoretical one
Exercise Completion Documentation: Participation records and exercise summary formatted for audit submission
WHY THIS ENGAGEMENT PAYS FOR ITSELF
A Tested Incident Response Program Reduces Risk, Strengthens Compliance, and Ensures Confident Response.

Satisfy Mandatory Incident Response Requirements
A tested, documented incident response plan fulfills FBI CJIS Security Policy obligations while providing defensible evidence of compliance and preparedness

Meet Critical Notification Deadlines
Mandatory breach notification timelines are non-negotiable, and a tested response process prevents additional compliance violations during high-pressure situations

Validate Compliance Program Maturity
Tabletop exercises reveal whether your team can apply Policy control requirements in practice and identify weaknesses before auditors or incidents expose them

Protect Leadership and Reduce Liability
A documented, validated incident response capability demonstrates due diligence, strengthens audit posture, and protects leadership from personal exposure following a CJI breach
Frequently Asked Questions
Do you need access to CJI to develop our IR plan or facilitate the exercise?
No. All plan development and exercise facilitation is conducted against your operational environment and existing documentation — not the data itself. In rare instances where CJI access is necessary, we will execute the required CJIS Security Addendum documentation to authorize it in full compliance with FBI CJIS Security Policy requirements.
Are tabletop exercises only about breach scenarios?
No — and this is an important distinction. Scenarios are designed to test working knowledge across multiple FBI CJIS Security Policy control families — access control, personnel security, audit logging, vendor management, mobile device controls, and more. The goal is to validate that your team can apply specific control requirements in practice, not just recite them from a document.
How is a CJIS-specific IR plan different from a standard cybersecurity IR plan?
A CJIS-specific plan addresses the notification timelines, mandatory reporting obligations, evidence preservation requirements, and escalation chains the FBI CJIS Security Policy imposes on CJI incidents specifically. A generic IR plan does not — and an auditor will know the difference immediately.
Who should participate in the tabletop exercise?
Everyone with a compliance role — IT and security staff, your CJIS Systems Officer, legal counsel, executive leadership, and relevant vendor contacts. The exercise is most valuable when the full team participates.
How often should tabletop exercises be conducted?
At minimum annually — and additionally after any significant change to your environment, vendor relationships, personnel, or applicable Policy requirements.
How long does this engagement take?
Four to six weeks for most engagements — two to three weeks for IR plan development and scenario design, followed by the exercise and after-action report.


