Skip to main content
Home > Solutions > Solutions by Standard > CJIS Security Policy MFA and Password Security

CJIS Security Policy
MFA and Password Security

The FBI CJIS Security Policy requires Advanced Authentication and strong password controls for all access to Criminal Justice Information. MyID® MFA delivers multi-factor authentication while MyID PSM screens every password against 11 billion+ breached credentials in real time.

CJIS Security Policy MFA and Password Security
CJIS Policy Coverage

How MyID MFA and PSM address CJIS Section 5.6

CJIS Policy 5.6.2.2

Advanced Authentication

MyID MFA provides FIDO2 hardware keys, Pattern Grid and push authentication, all meeting the CJIS Advanced Authentication requirement. Phishing-resistant methods available for the highest-risk CJI access.

CJIS Policy 5.6.2.1

Password Security

MyID PSM intercepts every Active Directory password change and validates against NIST 800-63B policy. Breached credentials are blocked before they enter the directory. Password stemming catches variants like P@ssword1.

CJIS Policy 5.4

Auditing and Accountability

MyID MFA and PSM generate an immutable audit trail of every authentication event and password change. Event codes written to the Windows Application Event Log for SIEM integration.

NIST SP 800-63B

Password Policy Compliance

MyID PSM enforces NIST 800-63B out of the box: minimum length (not complexity), breach database checking, password stemming, heuristic scanning, and custom blacklists. No manual policy configuration needed.

CJIS Policy 5.6.3

Offline and Field Authentication

MyID MFA's Pattern Grid and Windows Desktop Agent support offline authentication with encrypted local cache. Officers can authenticate to CJI systems in vehicles, temporary command posts and areas without network coverage.

CJIS Policy 5.8

Breach Response

MyID PSM's continuous breach monitoring alerts administrators when existing passwords appear in new breach disclosures. Combined with MyID MFA's instant credential controls, agencies can respond to compromised credentials within minutes.

CJIS Compliance

CJIS Requirements MyID Addresses

The MyID Suite delivers every authentication, password security and audit requirement specified in FBI CJIS Security Policy and 5.13.

Advanced Authentication (AA) via MyID MFA: FIDO2, Pattern Grid, push, TOTP and smart card methods for CJI access under Policy 5.6.2.2
Password breach screening via MyID PSM: every AD password change checked against 11 billion+ compromised credentials in real time
NIST 800-63B password policy via MyID PSM: length over complexity, stemming detection, keyboard walk blocking, custom blacklists
Audit logging of all authentication events and password changes: user, time, device, method and outcome
Offline authentication via MyID MFA: Pattern Grid works without network connectivity for officers in the field
Deployment

CJIS-compliant deployment options

MyID MFA and PSM share a single Authentication Server that stores all settings in Active Directory, requiring no separate database. Add a second server for native Active-Active high availability.

On-Premise (Recommended) Full control within the agency boundary. No CJI data traverses external networks. Domain Controller Agent intercepts password changes locally. Breach database available as a local offline copy (11B+ credentials).
Cloud / Hybrid Cloud-hosted breach checking via Intercede's secure API. Password hashes never leave the agency network: only k-anonymity partial hash sent to cloud service. Suitable for smaller agencies without dedicated infrastructure.
Air-Gapped / Offline MyID MFA's Pattern Grid provides offline authentication without any network connectivity. PSM's offline full database (11B+) runs entirely within the isolated network. No cloud calls required.
Compliance Mapping

CJIS Security Policy v5.9 mapping

CJIS Requirement MyID Coverage
5.6.2.2 Advanced Authentication MyID MFA: FIDO2, Pattern Grid, Push, TOTP
5.6.2.1 Password Management MyID PSM: 11B+ breach check, NIST 800-63B
5.6.3 Identification and Auth MyID MFA: all methods in one licence
5.4 Audit Logging Both: immutable event log, SIEM export
Offline / Field Authentication MyID MFA: Pattern Grid offline, encrypted cache
Encryption in Transit TLS 1.3 throughout
Breach Monitoring MyID PSM: continuous, 3M+ added daily
Context

Why CJIS compliance needs both MFA and password security

CJIS Policy 5.6 requires Advanced Authentication for CJI access, but strong authentication alone is not enough. Compromised passwords remain the leading initial access vector in law enforcement breaches. MyID MFA delivers the multi-factor authentication that satisfies Section 5.6.2.2, while MyID PSM ensures that every password in the Active Directory meets NIST 800-63B standards and is continuously screened against the world's largest database of breached credentials. Together, they close both the authentication and the credential hygiene gaps that auditors look for.

11B+
Breached credentials checked by MyID PSM
3M+
New compromised credentials added daily
Offline
Pattern Grid auth works without any network connectivity
Zero DB
All settings stored in AD, no separate database needed
Frequently Asked Questions

Common questions

Need something specific? Contact our team →

Any agency, contractor or individual that accesses Criminal Justice Information (CJI), including NCIC, III, NLETS and state systems, must comply with the CJIS Security Policy. This includes local police departments, county sheriffs, state agencies, federal agencies and private entities with CJI access such as background screening companies.

CJIS Security Policy Section 5.6.2.2 mandates Advanced Authentication (AA) for all remote access to CJI systems and for personnel accessing CJI from within a physically secure location using systems that are not CJIS compliant. AA requires two authentication factors from separate categories: something you know, have, or are.

SMS-based OTP has been debated within CJIS. The current policy allows it in some configurations, but NIST and FBI guidance increasingly favour phishing-resistant methods. Many state CJIS System Agencies (CSAs) now recommend hardware-based MFA. MyID MFA's FIDO2 and smart card methods provide the strongest CJIS compliance position.

Yes. MyID MFA and PSM are deployed by state and local law enforcement agencies across the US. On-premise deployment keeps all authentication data and breach checking within the agency boundary. The offline breach database (11B+ credentials) runs without any external connectivity. Our cleared team can support CJIS audit processes.

CJIS Policy 5.4 requires audit logs of all access to CJI systems including user identity, time, device and action. MyID generates an immutable audit trail of every authentication event, which user, which device, which method, success or failure, exportable in formats suitable for CJIS audit evidence.

CJIS Compliance

Ready to achieve CJIS Section 5.6 compliance?

Our law enforcement team can assess your current authentication and password security position against CJIS requirements and show you how MyID MFA and PSM close the gaps, at no cost during the demo.