simpl.
Government Command Center 16 items

CJIS Mobile Device & Advanced Authentication Checklist

Focuses on mobile device management and advanced (multi-factor) authentication controls for accessing Criminal Justice Information from the field.

CJIS Security PolicyFBI CJIS

Free PDF · enter your email to download.

Advanced Authentication

  • Is advanced (multi-factor) authentication enforced for access to Criminal Justice Information from non-secure locations? *
  • Does authentication use at least two of the three factors (knowledge, possession, inherence)? *
  • Are password/PIN composition and lifecycle requirements enforced for the knowledge factor? *

Mobile Device Management (MDM)

  • Is a centrally managed Mobile Device Management solution deployed to devices accessing CJI? *
  • Can the MDM enforce remote lock and remote wipe of a lost or stolen device? *
  • Are application whitelisting/blacklisting and OS version controls enforced through the MDM? *
  • Is device compromise (jailbreak/root) detection enabled? *

Encryption & Data Protection

  • Is CJI encrypted in transit using FIPS 140-validated cryptographic modules? *
  • Is CJI at rest on the mobile device encrypted? *
  • Is the device configured to lock automatically after a defined period of inactivity? *

Wireless & Network Access

  • Are secure connection methods (e.g., VPN with approved encryption) used over cellular and Wi-Fi? *
  • Is connection to unapproved public/open Wi-Fi networks prohibited for devices handling CJI? *
  • Is Bluetooth and other short-range wireless usage restricted to approved, secured pairings? *

Lifecycle & Incident Response

  • Is CJI sanitized from devices before reassignment or disposal? *
  • Is loss or theft of a mobile device reported and handled under the incident response plan? *
  • Are audit logs of CJI access from mobile devices generated and retained per policy? *

Download the full CJIS Mobile Device & Advanced Authentication Checklist checklist

Get it as a clean, printable PDF — free.