Muistiinpano
Tämän sivun käyttö edellyttää valtuutusta. Voit yrittää kirjautua sisään tai vaihtaa hakemistoa.
Tämän sivun käyttö edellyttää valtuutusta. Voit yrittää vaihtaa hakemistoa.
CJIS overview
The Criminal Justice Information Services (CJIS) Division of the US Federal Bureau of Investigation (FBI) gives state, local, and federal law enforcement and criminal justice agencies access to criminal justice information (CJI). CJI includes, for example, fingerprint records and criminal histories. Law enforcement and other government agencies in the United States must ensure that their use of cloud services for the transmission, storage, or processing of CJI complies with the CJIS Security Policy, which establishes minimum security requirements and controls to safeguard CJI.
The CJIS Security Policy integrates presidential and FBI directives, federal laws, and the criminal justice community's Advisory Policy Board (APB) decisions, along with guidance from the National Institute of Standards and Technology (NIST). The Policy is updated periodically to reflect evolving security requirements. The current version is CJIS Security Policy v6.1, effective June 25, 2026.
Beginning with version 6.0, the CJIS Security Policy is structured around the security control families defined in NIST SP 800-53 Revision 5, rather than the 13 policy areas used in version 5.x. Section 5 of the Policy now consists of Policy Area 1 (Information Exchange Agreements) followed by requirements organized under the NIST SP 800-53 Rev. 5 control families, including Access Control (AC), Awareness and Training (AT), Audit and Accountability (AU), Assessment, Authorization, and Monitoring (CA), Configuration Management (CM), Contingency Planning (CP), Identification and Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Physical and Environmental Protection (PE), Planning (PL), Program Management (PM), Personnel Security (PS), Risk Assessment (RA), System and Services Acquisition (SA), System and Communications Protection (SC), System and Information Integrity (SI), and Supply Chain Risk Management (SR).
This alignment with NIST SP 800-53 means that CJIS Security Policy requirements correspond closely to the control baselines used by the Federal Risk and Authorization Management Program (FedRAMP), a program under which Microsoft has been authorized for its Government Cloud offerings. Private contractors such as cloud service providers (CSPs) evaluate these control families to determine whether their services can be used consistently with CJIS requirements.
In addition, all private contractors who process CJI must sign the CJIS Security Addendum (Appendix H of the Policy), a uniform agreement approved by the US Attorney General that helps ensure the security and confidentiality of CJI required by the Security Policy. It also commits the contractor to maintaining a security program consistent with federal and state laws, regulations, and standards, and limits the use of CJI to the purposes for which a government agency provided it. Appendix G.3 of the Policy provides supplemental guidance specific to cloud computing environments, including personnel screening considerations for CSP personnel.
Roles defined in the CJIS Security Policy
Version 6.x of the CJIS Security Policy updated several role definitions in Section 3.2 that agencies and contractors should note when reviewing agreements and responsibilities:
- Contracting Agency (CA) — replaces the term Contracting Government Agency (CGA) used in version 5.x.
- Organizational Personnel with Security Responsibilities — replaces and broadens the Local Agency Security Officer (LASO) role.
- IA Official — replaces the Compact Officer role.
- State Compact Officer (SCO) — a role defined separately in version 6.x.
Identification, authentication, and encryption
The CJIS Security Policy requires multifactor authentication (MFA) for organizational users at Authenticator Assurance Level 2 (AAL2), as described in NIST SP 800-63 Digital Identity Guidelines. Authenticators and verifiers operated at AAL2 must be validated to meet Federal Information Processing Standard (FIPS) 140 Level 1 requirements.
The Policy also emphasizes protection of CJI throughout its lifecycle — in transit, at rest, and in use — and requires that CJI be stored and processed within the United States. Agencies are responsible for evaluating their encryption and key management approach, including customer-managed keys (CMK), when determining how CJIS requirements apply to their use of cloud services.
Microsoft and CJIS Security Policy
Microsoft signs the CJIS Security Addendum in states with CJIS Information Agreements. These agreements tell state law enforcement authorities responsible for compliance with CJIS Security Policy how Microsoft's cloud security controls help protect the full lifecycle of data and ensure appropriate background screening of operating personnel with access to CJI. Microsoft continues to work with state governments to enter into CJIS Information Agreements.
Microsoft has assessed the operational policies and procedures of Microsoft Azure Government, Microsoft Office 365 U.S. Government, and Microsoft Dynamics 365 U.S. Government, and will attest to their ability in the applicable services agreements to meet FBI requirements for the use of in-scope services.
Microsoft in-scope cloud platforms and services
- Azure Government
- Dynamics 365 U.S. Government
- Office 365 U.S. Government
- Power BI cloud service as part of an Office 365 Government Community Cloud branded plan or suite
Azure, Dynamics 365, and CJIS
For more information about Azure, Dynamics 365, and other online services compliance, see the Azure CJIS offering.
Office 365 and CJIS
Office 365 environments
Microsoft Office 365 is a multi-tenant hyperscale cloud platform and an integrated experience of apps and services available to customers in several regions worldwide. Most Office 365 services enable customers to specify the region where their customer data is located. Microsoft may replicate customer data to other regions within the same geographic area (for example, the United States) for data resiliency, but Microsoft will not replicate customer data outside the chosen geographic area.
This section covers the following Office 365 environments:
- Client software (Client): commercial client software running on customer devices.
- Office 365 (Commercial): the commercial public Office 365 cloud service available globally.
- Office 365 Government Community Cloud (GCC): the Office 365 GCC cloud service is available for United States Federal, State, Local, and Tribal governments, and contractors holding or processing data on behalf of the US Government.
- Office 365 Government Community Cloud - High (GCC High): the Office 365 GCC High cloud service is designed according to Department of Defense (DoD) Security Requirements Guidelines Level 4 controls and supports strictly regulated federal and defense information. This environment is used by federal agencies, the Defense Industrial Base (DIBs), and government contractors.
- Office 365 DoD (DoD): the Office 365 DoD cloud service is designed according to DoD Security Requirements Guidelines Level 5 controls and supports strict federal and defense regulations. This environment is for the exclusive use by the US Department of Defense.
Use this section to help meet your compliance obligations across regulated industries and global markets. To find out which services are available in which regions, see the International availability information and the Where your Microsoft 365 customer data is stored article. For more information about Office 365 Government cloud environment, see the Office 365 Government Cloud article.
Your organization is wholly responsible for ensuring compliance with all applicable laws and regulations. Information provided in this section does not constitute legal advice and you should consult legal advisors for any questions regarding regulatory compliance for your organization.
Office 365 applicability and in-scope services
Use the following table to determine applicability for your Office 365 services and subscription:
| Applicability | In-scope services |
|---|---|
| GCC | Activity Feed Service, Bing Services, Bookings, Delve, Exchange Online, Exchange Online Protection, Infrastructure, Intelligent Services, Microsoft 365 Copilot, Microsoft Teams, Office 365 Customer Portal, Office Online, Office Service, Office Usage Reports, OneDrive for Business, People Card, SharePoint Online, Windows Ink |
Office 365 audits, reports, and certificates
The FBI doesn't offer certification of Microsoft compliance with CJIS requirements. Instead, a Microsoft attestation is included in agreements between Microsoft and a state's CJIS authority, and between Microsoft and its customers.
CJIS status in the United States (current as of August 24, 2026)
There are CJIS Management Agreements covering criminal justice agencies in 47 states and the District of Columbia:
Alabama, Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, and the District of Columbia.
Microsoft's commitment to meeting the applicable CJIS regulatory controls allows criminal justice organizations to implement cloud-based solutions and be compliant with CJIS Security Policy v6.1.
Frequently asked questions
Where can I request compliance information?
Contact your Microsoft account representative for information on the jurisdiction you're interested in. Contact cjis@microsoft.com for information on which services are currently available in which states.
How does Microsoft demonstrate that its cloud services enable compliance with my state's requirements?
Microsoft signs an Information Agreement with a state CJIS Systems Agency (CSA); you can request a copy from your state's CSA. In addition, Microsoft provides customers with in-depth security, privacy, and compliance information. Customers can also review security and compliance reports prepared by independent auditors so they can validate that Microsoft implemented security controls (such as ISO 27001) appropriate to the relevant audit scope.
Where do I start with my agency's compliance effort?
The CJIS Security Policy covers the precautions that your agency must take to protect CJI. In addition, your Microsoft account representative can put you in touch with those familiar with the requirements of your jurisdiction.
How does CJIS Security Policy v6.1 change what my agency needs to do?
Version 6.x reorganized the Policy around NIST SP 800-53 Rev. 5 control families and updated several role definitions. Version 6.1 became effective June 25, 2026. Agencies should review their existing agreements, security policies, and audit artifacts against the current control-family structure, and confirm that MFA, encryption, and personnel screening practices align with the current requirements. Consult your state CSA and the CJIS Security Policy Resource Center for the authoritative requirements and any transition timelines.
Use Microsoft Purview Compliance Manager to assess your risk
Microsoft Purview Compliance Manager is a feature in the Microsoft Purview portal to help you understand your organization's compliance posture and take actions to help reduce risks. Compliance Manager offers a premium template for building an assessment for this regulation. Find the template in the assessment templates page in Compliance Manager. Learn how to build assessments in Compliance Manager.