Government Command Center 16 items
CJIS Mobile Device & Advanced Authentication Checklist
Focuses on mobile device management and advanced (multi-factor) authentication controls for accessing Criminal Justice Information from the field.
CJIS Security PolicyFBI CJIS
Free PDF · enter your email to download.
Advanced Authentication
- Is advanced (multi-factor) authentication enforced for access to Criminal Justice Information from non-secure locations? *
- Does authentication use at least two of the three factors (knowledge, possession, inherence)? *
- Are password/PIN composition and lifecycle requirements enforced for the knowledge factor? *
Mobile Device Management (MDM)
- Is a centrally managed Mobile Device Management solution deployed to devices accessing CJI? *
- Can the MDM enforce remote lock and remote wipe of a lost or stolen device? *
- Are application whitelisting/blacklisting and OS version controls enforced through the MDM? *
- Is device compromise (jailbreak/root) detection enabled? *
Encryption & Data Protection
- Is CJI encrypted in transit using FIPS 140-validated cryptographic modules? *
- Is CJI at rest on the mobile device encrypted? *
- Is the device configured to lock automatically after a defined period of inactivity? *
Wireless & Network Access
- Are secure connection methods (e.g., VPN with approved encryption) used over cellular and Wi-Fi? *
- Is connection to unapproved public/open Wi-Fi networks prohibited for devices handling CJI? *
- Is Bluetooth and other short-range wireless usage restricted to approved, secured pairings? *
Lifecycle & Incident Response
- Is CJI sanitized from devices before reassignment or disposal? *
- Is loss or theft of a mobile device reported and handled under the incident response plan? *
- Are audit logs of CJI access from mobile devices generated and retained per policy? *
Download the full CJIS Mobile Device & Advanced Authentication Checklist checklist
Get it as a clean, printable PDF — free.
