Skip to main content

FBI's CJIS v6.1: What Security Teams Need to Know.

0
Medium
News
Published: 09/21/2026 (09/21/2026, 14:02:12 UTC)
Source: Bleeping Computer

Description

The FBI's CJIS Security Policy version 6.1 updates encryption requirements and vulnerability scanning frequency for agencies handling Criminal Justice Information (CJI). It raises encryption strength for data in transit and at rest to at least 256-bit and requires monthly vulnerability scans instead of quarterly. While audit requirements are phased, agencies should prepare for more continuous assessments and stricter compliance verification, especially around password and multi-factor authentication (MFA) controls. The policy emphasizes stronger identity verification and device assurance but is not a Zero Trust standard. Agencies are encouraged to review and enhance password policies and MFA coverage to meet the updated requirements.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 14:16:54 UTC

Technical Analysis

CJIS Security Policy v6.1, published June 25, 2026, refines the modernized control-based framework introduced in v6.0 by increasing cryptographic protection requirements for CJI in transit and at rest to at least 256-bit strength. It also tightens vulnerability management by increasing scanning frequency from quarterly to monthly. Audit enforcement remains phased, with Priority 1 controls sanctionable since October 2024 and other priorities in zero-cycle status until September 2027. Identification and Authentication controls, including mandatory MFA for all accounts and quarterly password checks against compromised lists, remain consistent with v6.0. The policy encourages continuous assessment and stronger evidence of control effectiveness. Specops solutions are highlighted as tools to assist agencies in meeting password and MFA requirements. CJIS v6.1 aligns with principles similar to Zero Trust by emphasizing identity verification and device trust, though it is not formally a Zero Trust standard.

Potential Impact

The updated policy increases security requirements for agencies handling CJI by mandating stronger encryption and more frequent vulnerability scanning, which reduces the risk of data compromise. The emphasis on MFA for all accounts and maintaining lists of compromised passwords aims to mitigate credential-based breaches. The phased audit approach means agencies must progressively comply with these controls, with Priority 1 controls already enforceable. Failure to meet these requirements could result in audit findings and sanctions. The policy's focus on continuous assessment and evidence of control effectiveness increases operational security demands on agencies.

Defensive Guidance

Agencies should implement encryption with at least 256-bit strength for CJI in transit and at rest as required by SC-13 and SC-28 controls. Vulnerability scanning should be conducted at least monthly to comply with updated vulnerability management requirements. Organizations must enforce MFA for all privileged and non-privileged accounts and maintain and update lists of commonly used or compromised passwords quarterly, checking new passwords against these lists. Agencies should confirm current audit expectations with their State CJIS Systems Agencies (CSAs) due to phased audit enforcement. Utilizing tools like Specops Password Auditor, Password Policy, and Secure Access can assist in meeting password and MFA requirements and provide evidence for audits. Since the policy is not a Zero Trust standard but aligns with its principles, agencies may consider adopting device trust and least privilege access controls to further reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/","fetched":true,"fetchedAt":"2026-09-21T14:16:40.140Z","wordCount":1292}

Threat ID: 6ab13c4855bf5e2cf50313a7

Added to database: 09/21/2026, 14:16:40 UTC

Last enriched: 09/21/2026, 14:16:54 UTC

Last updated: 09/21/2026, 19:46:32 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses