CJIS Security Addendum

FBI Criminal Justice Information Services (CJIS) Security Policy Compliance

This addendum describes how J Computer Solutions LLC complies with the FBI CJIS Security Policy and the obligations of agencies and contractors accessing Criminal Justice Information (CJI) through Project Aziz.

1. Scope

This addendum applies to any use of Project Aziz involving Criminal Justice Information as defined in the FBI CJIS Security Policy. Not all uses of Project Aziz involve CJI — community users submitting tips and creating cases are not subject to CJIS requirements. CJIS requirements apply only to law enforcement agency access tiers.

2. Personnel Security

All J Computer Solutions LLC personnel with access to CJI are subject to a fingerprint-based background check submitted through IdentoGO / Fieldprint prior to access. Personnel are re-screened every 5 years or upon changes in role. Agency personnel accessing CJI through Project Aziz must be vetted through their own agency's CJIS security officer (CSO).

3. Access Control

Access to CJI within Project Aziz is enforced through: multi-factor authentication (MFA) required for all law enforcement accounts; role-based access control limiting CJI visibility to authorized personnel; automatic session timeouts after 30 minutes of inactivity; and no shared or generic accounts permitted.

4. Data Encryption

All CJI is encrypted in transit using TLS 1.3 or higher. CJI at rest is encrypted using AES-256. Encryption keys are managed through a dedicated key management system with key rotation on an annual schedule. Portable devices and field hardware use full-disk encryption.

5. Audit Logging

All access to CJI is logged, including user identity, timestamp, action performed, and data accessed. Audit logs are retained for a minimum of 3 years. Logs are protected from modification and reviewed monthly for anomalous activity.

6. Incident Response

In the event of a security incident involving CJI, J Computer Solutions LLC will: contain the incident within 1 hour; notify affected agencies within 24 hours; notify the relevant CJIS Systems Agency (CSA) within the time required by applicable policy; and provide a full incident report within 72 hours.

7. Security Awareness Training

All personnel with access to CJI complete CJIS Security Awareness Training within 6 months of hire and annually thereafter, consistent with FBI CJIS Security Policy requirements.

8. Execution

Agencies requiring a signed CJIS Security Addendum for their records management or procurement process should contact us via the contact page. A formal addendum signed by an authorized officer of J Computer Solutions LLC is available upon request.