CJIS Security Policy
MFA and Password Security
The FBI CJIS Security Policy requires Advanced Authentication and strong password controls for all access to Criminal Justice Information. MyID® MFA delivers multi-factor authentication while MyID PSM screens every password against 11 billion+ breached credentials in real time.

How MyID MFA and PSM address CJIS Section 5.6
Advanced Authentication
MyID MFA provides FIDO2 hardware keys, Pattern Grid and push authentication, all meeting the CJIS Advanced Authentication requirement. Phishing-resistant methods available for the highest-risk CJI access.
Password Security
MyID PSM intercepts every Active Directory password change and validates against NIST 800-63B policy. Breached credentials are blocked before they enter the directory. Password stemming catches variants like P@ssword1.
Auditing and Accountability
MyID MFA and PSM generate an immutable audit trail of every authentication event and password change. Event codes written to the Windows Application Event Log for SIEM integration.
Password Policy Compliance
MyID PSM enforces NIST 800-63B out of the box: minimum length (not complexity), breach database checking, password stemming, heuristic scanning, and custom blacklists. No manual policy configuration needed.
Offline and Field Authentication
MyID MFA's Pattern Grid and Windows Desktop Agent support offline authentication with encrypted local cache. Officers can authenticate to CJI systems in vehicles, temporary command posts and areas without network coverage.
Breach Response
MyID PSM's continuous breach monitoring alerts administrators when existing passwords appear in new breach disclosures. Combined with MyID MFA's instant credential controls, agencies can respond to compromised credentials within minutes.
CJIS Requirements MyID Addresses
The MyID Suite delivers every authentication, password security and audit requirement specified in FBI CJIS Security Policy and 5.13.
CJIS-compliant deployment options
MyID MFA and PSM share a single Authentication Server that stores all settings in Active Directory, requiring no separate database. Add a second server for native Active-Active high availability.
CJIS Security Policy v5.9 mapping
| CJIS Requirement | MyID Coverage |
|---|---|
| 5.6.2.2 Advanced Authentication | MyID MFA: FIDO2, Pattern Grid, Push, TOTP |
| 5.6.2.1 Password Management | MyID PSM: 11B+ breach check, NIST 800-63B |
| 5.6.3 Identification and Auth | MyID MFA: all methods in one licence |
| 5.4 Audit Logging | Both: immutable event log, SIEM export |
| Offline / Field Authentication | MyID MFA: Pattern Grid offline, encrypted cache |
| Encryption in Transit | TLS 1.3 throughout |
| Breach Monitoring | MyID PSM: continuous, 3M+ added daily |
Why CJIS compliance needs both MFA and password security
CJIS Policy 5.6 requires Advanced Authentication for CJI access, but strong authentication alone is not enough. Compromised passwords remain the leading initial access vector in law enforcement breaches. MyID MFA delivers the multi-factor authentication that satisfies Section 5.6.2.2, while MyID PSM ensures that every password in the Active Directory meets NIST 800-63B standards and is continuously screened against the world's largest database of breached credentials. Together, they close both the authentication and the credential hygiene gaps that auditors look for.
Common questions
Need something specific? Contact our team →
Any agency, contractor or individual that accesses Criminal Justice Information (CJI), including NCIC, III, NLETS and state systems, must comply with the CJIS Security Policy. This includes local police departments, county sheriffs, state agencies, federal agencies and private entities with CJI access such as background screening companies.
CJIS Security Policy Section 5.6.2.2 mandates Advanced Authentication (AA) for all remote access to CJI systems and for personnel accessing CJI from within a physically secure location using systems that are not CJIS compliant. AA requires two authentication factors from separate categories: something you know, have, or are.
SMS-based OTP has been debated within CJIS. The current policy allows it in some configurations, but NIST and FBI guidance increasingly favour phishing-resistant methods. Many state CJIS System Agencies (CSAs) now recommend hardware-based MFA. MyID MFA's FIDO2 and smart card methods provide the strongest CJIS compliance position.
Yes. MyID MFA and PSM are deployed by state and local law enforcement agencies across the US. On-premise deployment keeps all authentication data and breach checking within the agency boundary. The offline breach database (11B+ credentials) runs without any external connectivity. Our cleared team can support CJIS audit processes.
CJIS Policy 5.4 requires audit logs of all access to CJI systems including user identity, time, device and action. MyID generates an immutable audit trail of every authentication event, which user, which device, which method, success or failure, exportable in formats suitable for CJIS audit evidence.