top of page
CJIS Compliance Company.jpg
Incident Response Tabletop Exercises.png

Incident Response Planning & Tabletop Exercises

When It Comes to CJIS Compliance, Knowing the Policy and Proving You Can Execute It Are Two Very Different Things.

A documented incident response plan and a tested, operational compliance posture are not the same thing. The FBI CJIS Security Policy demands both — and auditors are increasingly focused on whether your organization can demonstrate real-world execution, not just policy awareness.

Learn More

WHO THIS SERVICE IS FOR

Criminal Justice Agencies (CJA), Noncriminal Justice Agencies (NCJA), Interface Agencies (IA), vendors, and any organization that processes, stores, or transmits Criminal Justice Information.

THE PROBLEM YOU'RE FACING

Most organizations have a generic incident response plan — borrowed from a template or inherited from an IT department that has never thought specifically about CJI breach notification requirements. When an actual CJI incident occurs, that plan fails at the moment it is needed most.

The deeper problem is that most organizations have never stress-tested their compliance posture against the actual control requirements of the FBI CJIS Security Policy. Staff have attended training and signed acknowledgment forms — but when placed in a realistic scenario requiring them to apply specific control knowledge, gaps surface immediately.

Tabletop exercises exist to find those gaps before an auditor does. They are not exclusively breach simulations — they are structured, scenario-driven compliance validation tools that test your team's working knowledge of FBI CJIS Security Policy controls across every applicable area.

Sound Familiar?

warning symbol.png
warning symbol.png
warning symbol.png
warning symbol.png
warning symbol.png
warning symbol.png

Non-Compliant Incident Response Planning: Your incident response plan was not written with FBI CJIS Security Policy breach notification requirements in mind

Untested Staff Response Capabilities: Your staff has completed training but has never been tested on applying specific control requirements in practice

No CJIS-Specific Tabletop Exercises: Your organization has never conducted a tabletop exercise scoped to FBI CJIS Security Policy control requirements

Undefined Breach Notification Procedures: Your breach notification timelines, reporting chains, and escalation procedures are undefined or out of date

Unvalidated Policy Knowledge: Your CJIS Systems Officer and IT staff know the Policy exists but have never had their working knowledge formally validated

Unresolved Incident Response Findings: A prior audit cited incident response deficiencies that were acknowledged but never fully addressed

CJIS Compliance Assessments.png

An untested compliance program is not a compliance program — it is a collection of documents. Until your people are forced to apply those procedures under realistic conditions, you have no way of knowing whether they will perform as intended when an actual incident occurs.

OUR METHODOLOGY

The CJIS Academy Incident Response Planning and Tabletop Exercise engagement builds a CJIS-specific incident response capability and validates your team's operational compliance knowledge through structured, scenario-driven exercises built directly against FBI CJIS Security Policy control requirements.

CJIS Compliance Gap Assessments.png

PHASE 1:

Current State Assessment

Existing incident response documentation, breach notification procedures, and escalation protocols are assessed directly against FBI CJIS Security Policy requirements. Gaps are identified and scoped for development.

CJIS Compliance Gap Assessments.png

PHASE 2:

CJIS-Specific IR Plan Development

A purpose-built CJIS incident response plan is developed covering CJI incident detection and classification, containment procedures, mandatory breach notification timelines, communication protocols, evidence preservation, and post-incident review — built to Policy specification, not adapted from a generic template.

CJIS Compliance Gap Assessments.png

PHASE 3:

Tabletop Exercise Design

Scenarios are designed and scoped to your specific environment — your systems, vendors, personnel, and applicable FBI CJIS Security Policy control obligations. Exercises test working knowledge across multiple control families — access control, personnel security, audit logging, vendor obligations, mobile device controls, and breach notification. Every scenario is built to surface real gaps, not produce comfortable results.

CJIS Compliance Gap Assessments.png

PHASE 4:

Facilitated Tabletop Exercise

The exercise is facilitated with your full compliance team — IT, security, your CJIS Systems Officer, legal counsel, and executive leadership. Participants work through scenarios in real time, applying specific FBI CJIS Security Policy control requirements to realistic situations. Knowledge gaps, role confusion, and procedural breakdowns are captured as they occur.

CJIS Compliance Gap Assessments.png

PHASE 5:

After-Action Report & Plan Remediation

Every finding is documented — knowledge gaps, procedural breakdowns, notification timelines missed, control requirements misapplied. The IR plan and relevant operational procedures are revised to address every finding before the engagement closes.

Quotation Marks.png

Tabletop exercises are the most honest assessment of a CJIS compliance program's operational maturity available. It's one thing to have a policy document — it's another thing entirely to put your team in a realistic scenario and find out whether they actually know what the FBI CJIS Security Policy requires them to do.

— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

cybersecurity Speaker Charles Denyer.jpg

Incident Response Planning & Tabletop Exercises PACKAGE

Every incident response planning and tabletop exercise engagement produces a complete, audit-ready deliverable package.

Audit-Defensible Documentation Expert.png

All documents are delivered in editable format, formatted for professional presentation, and built to be maintained by your team without ongoing outside support.

WHAT YOU RECEIVE

CJIS Incident Response Plan: Purpose-built to FBI CJIS Security Policy specification, covering breach notification timelines, mandatory reporting obligations, containment procedures, and post-incident review protocols

Breach Notification Procedures: Documented timelines, reporting chains, and escalation procedures for every required notification party

Tabletop Exercise Scenario Package: Full scenario design, inject sequence, and facilitator guide, available for reuse in future internal exercises

After-Action Report: Formal documentation of every gap, knowledge deficiency, and procedural breakdown identified, with remediation mapped to specific Policy control requirements

Revised & Validated IR Plan: Updated to address every after-action finding, producing a tested document rather than a theoretical one

Exercise Completion Documentation: Participation records and exercise summary formatted for audit submission

WHY THIS ENGAGEMENT PAYS FOR ITSELF

A Tested Incident Response Program Reduces Risk, Strengthens Compliance, and Ensures Confident Response.

CJIS Compliance Gap Assessment Services.png

Satisfy Mandatory Incident Response Requirements

A tested, documented incident response plan fulfills FBI CJIS Security Policy obligations while providing defensible evidence of compliance and preparedness

CJIS Compliance Gap Assessment Services.png

Meet Critical Notification Deadlines

Mandatory breach notification timelines are non-negotiable, and a tested response process prevents additional compliance violations during high-pressure situations

CJIS Compliance Gap Assessment Services.png

Validate Compliance Program Maturity

Tabletop exercises reveal whether your team can apply Policy control requirements in practice and identify weaknesses before auditors or incidents expose them

CJIS Compliance Gap Assessment Services.png

Protect Leadership and Reduce Liability

A documented, validated incident response capability demonstrates due diligence, strengthens audit posture, and protects leadership from personal exposure following a CJI breach

Frequently Asked Questions

Do you need access to CJI to develop our IR plan or facilitate the exercise?

No. All plan development and exercise facilitation is conducted against your operational environment and existing documentation — not the data itself. In rare instances where CJI access is necessary, we will execute the required CJIS Security Addendum documentation to authorize it in full compliance with FBI CJIS Security Policy requirements.

Are tabletop exercises only about breach scenarios?

No — and this is an important distinction. Scenarios are designed to test working knowledge across multiple FBI CJIS Security Policy control families — access control, personnel security, audit logging, vendor management, mobile device controls, and more. The goal is to validate that your team can apply specific control requirements in practice, not just recite them from a document.

How is a CJIS-specific IR plan different from a standard cybersecurity IR plan?

A CJIS-specific plan addresses the notification timelines, mandatory reporting obligations, evidence preservation requirements, and escalation chains the FBI CJIS Security Policy imposes on CJI incidents specifically. A generic IR plan does not — and an auditor will know the difference immediately.

Who should participate in the tabletop exercise?

Everyone with a compliance role — IT and security staff, your CJIS Systems Officer, legal counsel, executive leadership, and relevant vendor contacts. The exercise is most valuable when the full team participates.

How often should tabletop exercises be conducted?

At minimum annually — and additionally after any significant change to your environment, vendor relationships, personnel, or applicable Policy requirements.

How long does this engagement take?

Four to six weeks for most engagements — two to three weeks for IR plan development and scenario design, followed by the exercise and after-action report.​

FBI CJIS Compliance.png

Ready to Find Out Whether Your Compliance Program Works Under Pressure? START HERE.

Documented compliance and operational compliance are not the same thing. CJIS Academy builds the plan, designs the scenarios, facilitates the exercise, and closes every gap the exercise surfaces — so that when an auditor probes your team's control knowledge or an actual CJI incident occurs, your organization knows exactly what to do, in what order, and on whose authority.

Schedule a no-obligation intake call.  We'll assess your current incident response posture, scope the engagement, and deliver a fixed-fee proposal — before you commit to anything.

BG 2.jpg
CJIS Academy Logo

OUR LOCATIONS

Dallas, TX

12222 Merit Dr., Suite 130

Dallas, TX 75251

Irvine, CA

300 Spectrum Center Dr. Ste., 400, Irvine, CA 92618

  • LinkedIn
  • Youtube

Know your real CJIS v6.0 readiness in minutes—FREE. Our self-scoring CJIS Compliance Ready Workbook – one workbook for agencies (CJAs & NCJAs), one for the vendors who serve them – walks you through all 20 policy areas of the FBI CJIS Security Policy v6.0—all in one spreadsheet. Answer the questions and watch your readiness score, priority gaps, and 90-day roadmap build themselves, complete with the exact policies, procedures, and plans your auditor will ask to see.

Every question is mapped to CJIS v6.0 and its NIST 800-53 controls, so you're measured against what your CSA and the FBI actually check—not a generic checklist.

​Built for both sides of CJIS—one workbook for agencies (CJAs & NCJAs), one for the vendors who serve them.

Workbook Features:

All 20 CJIS v6.0 Policy Areas, Scored

No Credit Card Required. No login. Built for CJIS.

Sanctionable P1 Gaps, Flagged

Every Required Document, Mapped and Tracked

A Built-in 90-Day Roadmap Before Your Triennial Audit

Works in Excel—No Subscription, Yours to Keep

Stop Guessing Where You Stand on CJIS Compliance.

© Copyright 2020 by CJISAcademy.com. All Rights Reserved.

bottom of page