top of page
CJIS Compliance Company.jpg
Who has Your CJI.png

Who Has
Your CJI?

TM

You Think You Know Who Has Access to Your Criminal Justice Information. You Probably Don't.

This is not a hypothetical. It is not a worst-case scenario. It is the single most consistent finding across every CJIS compliance engagement conducted in the field — inside agencies, inside vendors, inside every organization that touches Criminal Justice Information. The wrong people have access. Too many people have access. And in most cases, nobody has ever formally verified who those people are, whether they should have access at all, or whether the access they have matches any legitimate, documented, policy-compliant need.

Learn More

WHO THIS SERVICE IS FOR

Criminal Justice Agencies (CJA), Noncriminal Justice Agencies (NCJA), Interface Agencies (IA), vendors, and any organization that processes, stores, or transmits Criminal Justice Information.

THE PROBLEM YOU'RE FACING

Criminal Justice Information is among the most sensitive, most regulated, and most consequential data in the country. It carries the weight of law enforcement investigations, criminal histories, biometric records, and intelligence that directly affects public safety. The FBI CJIS Security Policy exists precisely because unauthorized access to CJI is not an abstract compliance risk — it is a real-world threat with real-world consequences. 

And yet in practice, CJI access sprawls. It sprawls inside agencies — to staff who were granted access years ago and never had it reviewed, to personnel whose roles changed but whose access didn't, to contractors who finished their engagement and somehow retained system credentials. It sprawls outside agencies — to vendors whose employees were never properly vetted, to subcontractors nobody knew existed, to managed service providers whose technicians access CJI-adjacent systems without a signed Security Addendum or a background check on record.

The FBI CJIS Security Policy is explicit. Every individual who accesses CJI must be properly vetted, authorized, and operating within a defined and documented scope of need. Not most individuals. Not the ones you know about. Every individual.

Sound Familiar?

warning symbol.png
warning symbol.png
warning symbol.png
warning symbol.png
warning symbol.png
warning symbol.png

No Complete Access Inventory: You cannot produce a current, complete list of every individual — internal and external — with access to CJI in your environment right now

Unreviewed Access Authorizations: Access authorizations were granted years ago and have never been formally reviewed or revalidated

Unverified Vendor Personnel Access: Vendor and contractor personnel are accessing CJI-adjacent systems without verified background screening status on record

Improper Access After Personnel Changes: Personnel have changed roles, departments, or employment status, and their CJI access was never adjusted or terminated accordingly

Unassessed Third-Party Access Exposure: Subcontractors and downstream vendor relationships exist that your agency or organization has never formally assessed for CJI access scope

Unknown CJI Access Universe: Nobody in your organization can answer the question with certainty: Who has your CJI?

CJIS Compliance Assessments.png

If you cannot answer that question, you have a problem. Unauthorized access cannot be managed, justified, or remediated if it has never been identified in the first place. Before you can protect Criminal Justice Information, you must establish absolute certainty about who has access, why they have it, and whether that access remains authorized today. This is where it stops.

OUR METHODOLOGY

Who Has Your CJI?™ is a comprehensive, individual-level audit of every person — internal and external — with access to Criminal Justice Information in your environment. Every individual is assessed against FBI CJIS Security Policy personnel security requirements. Unauthorized access is terminated. Controls are built to prevent it from recurring.

CJIS Compliance Gap Assessments.png

PHASE 1:

CJI Access Universe Mapping

We build a complete, verified inventory of every individual with access to CJI in your environment — sworn personnel, civilian staff, contractors, vendors, subcontractors, managed service providers, and any other third party whose role, system access, or physical presence puts them in contact with Criminal Justice Information. Most organizations have never done this. The results are almost always surprising.

CJIS Compliance Gap Assessments.png

PHASE 2:

dividual-Level Personnel Security Verification

Every individual in the access universe is assessed against FBI CJIS Security Policy personnel security requirements — background screening status, security awareness training completion, need-to-know justification, access authorization documentation, and scope boundaries. Each individual is assessed independently. There are no assumptions, no blanket approvals, and no exceptions without documented justification.

CJIS Compliance Gap Assessments.png

PHASE 3:

Unauthorized Access Identification & Termination

Every individual whose access cannot be justified against FBI CJIS Security Policy requirements is identified and flagged for immediate access termination. This includes internal personnel whose roles no longer require CJI access, former employees or contractors whose access was never revoked, and vendor or subcontractor personnel who were never properly vetted or authorized in the first place.

CJIS Compliance Gap Assessments.png

PHASE 4:

Access Control Remediation

The structural gaps that allowed unauthorized access to exist are identified and closed — access provisioning processes, offboarding procedures, vendor onboarding controls, periodic access review cadences, and the documentation infrastructure required to keep CJI access authorized, current, and auditable on an ongoing basis.

CJIS Compliance Gap Assessments.png

PHASE 5:

Ongoing Access Governance Framework

Who Has Your CJI?™ doesn't end with the initial audit. A formal access governance framework is established — defining how CJI access is requested, approved, documented, reviewed, and terminated on a structured, recurring basis. The goal is not just to answer the question today. It is to make sure you can answer it accurately at any point in the future.

Quotation Marks.png

In every engagement I conduct, the answer to 'who has your CJI?' is always the same — more people than you think, many of whom have no business having it. This isn't a technology problem. It's a people problem. And it requires an expert to go through every individual, one by one, and verify whether their access is legitimate, documented, and policy-compliant.

— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

CJI Compliance Services.png

Who Has Your CJI  PACKAGE

™ 

Our WHO HAS YOUR CJI engagment produces the most operationally consequential deliverable package in the CJIS Academy portfolio.

Audit-Defensible Documentation Expert.png

All documents are delivered in editable format, formatted for professional presentation, and built to be maintained by your team without ongoing outside support.

WHAT YOU RECEIVE

Complete CJI Access Universe Inventory: A verified, documented registry of every individual with CJI access across your entire environment — internal and external

Individual-Level Personnel Security Assessment Report: A finding-by-finding accounting of every individual assessed, their compliance status against FBI CJIS Security Policy personnel security requirements, and the specific gaps identified

Unauthorized Access Termination Log: A documented record of every individual whose access was identified as unauthorized and the termination actions taken

Access Control Remediation Plan: A structured remediation of every process, procedure, and system gap that allowed unauthorized access to exist

CJI Access Governance Framework: Formal policies, procedures, and tracking tools governing how CJI access is requested, approved, reviewed, and terminated on an ongoing basis

Audit-Ready Personnel Security Evidence Package: Complete documentation formatted for CSA auditor review, evidencing the current authorized access universe and the controls governing it

WHY THIS ENGAGEMENT PAYS FOR ITSELF

Unauthorized CJI Access is not a Documentation Finding — it is a Policy Violation with Consequences that Extend Well Beyond an Audit Report.

CJIS Compliance Gap Assessment Services.png

Eliminate Unauthorized Access Risk

Unauthorized CJI access is the most common and most serious compliance failure in the field. This engagement identifies, removes, and prevents unauthorized access on a permanent basis.

CJIS Compliance Gap Assessment Services.png

Satisfy Auditor Scrutiny on Personnel Security

Personnel security is one of the most heavily examined areas in a CSA audit, and a verified, documented, current access universe removes an auditor's most productive line of questioning.

CJIS Compliance Gap Assessment Services.png

Protect Against Internal and External Threats

Internal personnel with unnecessary access, along with unvetted vendors and subcontractors, represent significant and often overlooked sources of compliance and security risk.

CJIS Compliance Gap Assessment Services.png

Build a Defensible Access Record

In the event of a CJI breach, the first question asked is who had access. This engagement ensures you can answer that question completely, accurately, and immediately with supporting documentation in hand.

Frequently Asked Questions

Do you need access to CJI to conduct this audit?

No. Who Has Your CJI?™ is conducted entirely against your access control systems, personnel records, vendor documentation, and the infrastructure that stores, processes, or transmits CJI — not the data itself. In rare instances where CJI access is necessary for sensitive consultative engagements, we will execute the required CJIS Security Addendum documentation to authorize it in full compliance with FBI CJIS Security Policy requirements.

​​​

What if we discover that a large number of individuals have unauthorized access?

That is exactly what this engagement is designed to find — and it is more common than most organizations expect. Unauthorized access identified through a proactive audit is a compliance problem you control. Unauthorized access discovered by an auditor or during a breach investigation is a compliance failure you explain. The engagement is built to handle findings at any scale.

Does this cover vendors and subcontractors as well as internal staff?

Yes. The CJI access universe mapped in Phase 1 includes every individual — internal and external — whose role, system access, or physical presence puts them in contact with Criminal Justice Information. Vendors, subcontractors, managed service providers, and any downstream third-party relationships are included in scope.

How is this different from a standard gap assessment?

A gap assessment evaluates your compliance posture across all 18 FBI CJIS Security Policy control families at a program level. Who Has Your CJI?™ is an individual-level audit focused exclusively on personnel security — going person by person through your entire CJI access universe to verify that every individual with access is authorized, vetted, and operating within a documented and policy-compliant scope.

What happens after unauthorized access is terminated?

The access control remediation in Phase 4 closes the structural gaps that allowed unauthorized access to exist in the first place — so terminating today's unauthorized access doesn't simply open the door for tomorrow's. The governance framework established in Phase 5 keeps your access universe current, authorized, and auditable on an ongoing basis.

How long does this engagement take?

Most engagements are completed within four to eight weeks, depending on the size of your organization, the complexity of your vendor relationships, and the depth of your existing access control documentation. A firm timeline is established during scoping.

FBI CJIS Compliance.png

Ready to Answer the Question Every CJIS Auditor Will Eventually Ask? START HERE.

Who has your CJI? If you cannot answer that question completely, accurately, and immediately — you have unauthorized access somewhere in your environment. CJIS Academy will find it, terminate it, and build the controls that make sure it never happens again.

Schedule a no-obligation intake call.  We'll scope the engagement, walk you through the methodology, and deliver a fixed-fee proposal — before you commit to anything.

BG 2.jpg
CJIS Academy Logo

OUR LOCATIONS

Dallas, TX

12222 Merit Dr., Suite 130

Dallas, TX 75251

Irvine, CA

300 Spectrum Center Dr. Ste., 400, Irvine, CA 92618

  • LinkedIn
  • Youtube

Know your real CJIS v6.0 readiness in minutes—FREE. Our self-scoring CJIS Compliance Ready Workbook – one workbook for agencies (CJAs & NCJAs), one for the vendors who serve them – walks you through all 20 policy areas of the FBI CJIS Security Policy v6.0—all in one spreadsheet. Answer the questions and watch your readiness score, priority gaps, and 90-day roadmap build themselves, complete with the exact policies, procedures, and plans your auditor will ask to see.

Every question is mapped to CJIS v6.0 and its NIST 800-53 controls, so you're measured against what your CSA and the FBI actually check—not a generic checklist.

​Built for both sides of CJIS—one workbook for agencies (CJAs & NCJAs), one for the vendors who serve them.

Workbook Features:

All 20 CJIS v6.0 Policy Areas, Scored

No Credit Card Required. No login. Built for CJIS.

Sanctionable P1 Gaps, Flagged

Every Required Document, Mapped and Tracked

A Built-in 90-Day Roadmap Before Your Triennial Audit

Works in Excel—No Subscription, Yours to Keep

Stop Guessing Where You Stand on CJIS Compliance.

© Copyright 2020 by CJISAcademy.com. All Rights Reserved.

bottom of page