FBI's CJIS v6.1: What Security Teams Need to Know.
The FBI's CJIS Security Policy version 6.1 updates encryption requirements and vulnerability scanning frequency for agencies handling Criminal Justice Information (CJI). It raises encryption strength for data in transit and at rest to at least 256-bit and requires monthly vulnerability scans instead of quarterly. While audit requirements are phased, agencies should prepare for more continuous assessments and stricter compliance verification, especially around password and multi-factor authentication (MFA) controls. The policy emphasizes stronger identity verification and device assurance but is not a Zero Trust standard. Agencies are encouraged to review and enhance password policies and MFA coverage to meet the updated requirements.
AI Analysis
Technical Summary
CJIS Security Policy v6.1, published June 25, 2026, refines the modernized control-based framework introduced in v6.0 by increasing cryptographic protection requirements for CJI in transit and at rest to at least 256-bit strength. It also tightens vulnerability management by increasing scanning frequency from quarterly to monthly. Audit enforcement remains phased, with Priority 1 controls sanctionable since October 2024 and other priorities in zero-cycle status until September 2027. Identification and Authentication controls, including mandatory MFA for all accounts and quarterly password checks against compromised lists, remain consistent with v6.0. The policy encourages continuous assessment and stronger evidence of control effectiveness. Specops solutions are highlighted as tools to assist agencies in meeting password and MFA requirements. CJIS v6.1 aligns with principles similar to Zero Trust by emphasizing identity verification and device trust, though it is not formally a Zero Trust standard.
Potential Impact
The updated policy increases security requirements for agencies handling CJI by mandating stronger encryption and more frequent vulnerability scanning, which reduces the risk of data compromise. The emphasis on MFA for all accounts and maintaining lists of compromised passwords aims to mitigate credential-based breaches. The phased audit approach means agencies must progressively comply with these controls, with Priority 1 controls already enforceable. Failure to meet these requirements could result in audit findings and sanctions. The policy's focus on continuous assessment and evidence of control effectiveness increases operational security demands on agencies.
Mitigation Recommendations
Agencies should implement encryption with at least 256-bit strength for CJI in transit and at rest as required by SC-13 and SC-28 controls. Vulnerability scanning should be conducted at least monthly to comply with updated vulnerability management requirements. Organizations must enforce MFA for all privileged and non-privileged accounts and maintain and update lists of commonly used or compromised passwords quarterly, checking new passwords against these lists. Agencies should confirm current audit expectations with their State CJIS Systems Agencies (CSAs) due to phased audit enforcement. Utilizing tools like Specops Password Auditor, Password Policy, and Secure Access can assist in meeting password and MFA requirements and provide evidence for audits. Since the policy is not a Zero Trust standard but aligns with its principles, agencies may consider adopting device trust and least privilege access controls to further reduce risk.
FBI's CJIS v6.1: What Security Teams Need to Know.
Description
The FBI's CJIS Security Policy version 6.1 updates encryption requirements and vulnerability scanning frequency for agencies handling Criminal Justice Information (CJI). It raises encryption strength for data in transit and at rest to at least 256-bit and requires monthly vulnerability scans instead of quarterly. While audit requirements are phased, agencies should prepare for more continuous assessments and stricter compliance verification, especially around password and multi-factor authentication (MFA) controls. The policy emphasizes stronger identity verification and device assurance but is not a Zero Trust standard. Agencies are encouraged to review and enhance password policies and MFA coverage to meet the updated requirements.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CJIS Security Policy v6.1, published June 25, 2026, refines the modernized control-based framework introduced in v6.0 by increasing cryptographic protection requirements for CJI in transit and at rest to at least 256-bit strength. It also tightens vulnerability management by increasing scanning frequency from quarterly to monthly. Audit enforcement remains phased, with Priority 1 controls sanctionable since October 2024 and other priorities in zero-cycle status until September 2027. Identification and Authentication controls, including mandatory MFA for all accounts and quarterly password checks against compromised lists, remain consistent with v6.0. The policy encourages continuous assessment and stronger evidence of control effectiveness. Specops solutions are highlighted as tools to assist agencies in meeting password and MFA requirements. CJIS v6.1 aligns with principles similar to Zero Trust by emphasizing identity verification and device trust, though it is not formally a Zero Trust standard.
Potential Impact
The updated policy increases security requirements for agencies handling CJI by mandating stronger encryption and more frequent vulnerability scanning, which reduces the risk of data compromise. The emphasis on MFA for all accounts and maintaining lists of compromised passwords aims to mitigate credential-based breaches. The phased audit approach means agencies must progressively comply with these controls, with Priority 1 controls already enforceable. Failure to meet these requirements could result in audit findings and sanctions. The policy's focus on continuous assessment and evidence of control effectiveness increases operational security demands on agencies.
Defensive Guidance
Agencies should implement encryption with at least 256-bit strength for CJI in transit and at rest as required by SC-13 and SC-28 controls. Vulnerability scanning should be conducted at least monthly to comply with updated vulnerability management requirements. Organizations must enforce MFA for all privileged and non-privileged accounts and maintain and update lists of commonly used or compromised passwords quarterly, checking new passwords against these lists. Agencies should confirm current audit expectations with their State CJIS Systems Agencies (CSAs) due to phased audit enforcement. Utilizing tools like Specops Password Auditor, Password Policy, and Secure Access can assist in meeting password and MFA requirements and provide evidence for audits. Since the policy is not a Zero Trust standard but aligns with its principles, agencies may consider adopting device trust and least privilege access controls to further reduce risk.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/","fetched":true,"fetchedAt":"2026-09-21T14:16:40.140Z","wordCount":1292}
Threat ID: 6ab13c4855bf5e2cf50313a7
Added to database: 09/21/2026, 14:16:40 UTC
Last enriched: 09/21/2026, 14:16:54 UTC
Last updated: 09/21/2026, 19:46:32 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.