CJIS Audit Readiness
Preparing for a CJIS audit shouldn't start when the auditor calls.
Last reviewed: September 2026
A practical checklist for smaller departments preparing their policies, documentation, people, and systems for a CJIS security audit.
For a smaller police department, CJIS compliance can feel disproportionately complicated.
The same people responsible for patrol, records, training, IT coordination, and day-to-day operations may also be responsible for making sure the agency can demonstrate how it protects Criminal Justice Information.
And that's an important distinction:
Having a security practice and being able to demonstrate that practice are not always the same thing.
An agency may be doing the right thing operationally but still have trouble during an audit because a policy was never formally adopted, a review wasn't documented, a vendor agreement can't be located, or nobody can produce the log showing that a required activity actually occurred.
This checklist is designed to help a smaller Texas law-enforcement agency ask a simple question:
If an auditor asked us to show this today, could we?
Before you use this checklist
For current Texas audit preparation, use the requirements and materials published by the Texas DPS CJIS Security Office as the authoritative source.
As of September 2026, Texas DPS says:
- CJIS Security Policy v5.9.5 is the current audit policy in Texas through March 31, 2027.
- CJIS Security Policy v6.1 was released June 25, 2026, and agencies should begin gap assessments for the newer requirements.
- Texas agencies also need to account for the Texas Security Policy Supplement and applicable Texas-specific requirements.
The quick check
Before getting into the details, see how many of these questions you can answer yes to today.
Leadership & responsibility
- We know who our Local Agency Security Officer (LASO) is.
- Staff know who to contact when they have a CJIS/security question.
- Responsibility for maintaining CJIS documentation is clear.
- Our policies identify actual agency roles and procedures rather than simply repeating policy language.
People & access
- Every person with CJI access has appropriate authorization.
- Required personnel screening/background requirements are documented.
- CJIS security training is current and documented.
- User accounts belong to individual users rather than being shared.
- We can quickly disable access when an employee leaves or changes roles.
- We periodically review who still has access.
Policies
- Required security policies are documented and approved.
- Policies reflect what our agency actually does.
- Required policy reviews are documented.
- Staff who need to know a policy can find it.
Devices & systems
- We know which computers, mobile devices, servers, and systems access or contain CJI.
- Authentication/MFA requirements are implemented where applicable.
- Devices are appropriately secured.
- Software and operating systems are maintained and patched.
- Remote access is controlled.
- Lost or stolen device procedures are documented.
Physical security
- Areas containing systems or information with CJI are appropriately controlled.
- Visitors are handled according to agency policy.
- Physical access procedures are documented.
- Printed CJI isn't left accessible to unauthorized people.
Vendors
- We know which vendors or contractors may have access to CJI.
- Required CJIS agreements/addenda are in place.
- Applicable vendor personnel requirements have been addressed.
- We understand where vendors store/process our CJI.
- We know what happens if a vendor experiences a security incident.
Incident response
- We have a documented incident-response plan.
- Employees know how to report a suspected incident.
- Current CJIS/DPS reporting contacts and procedures are available.
- The plan identifies who is responsible for what.
- The agency has reviewed/tested its response process as required.
Audit evidence
- We can produce access/account records.
- We can produce training records.
- We can produce required logs/reviews.
- We can produce applicable vendor agreements.
- We can produce our current policies.
- We can demonstrate that required recurring activities actually occurred.
Any unchecked box is a good place to start.
1. Know who owns CJIS security at your agency
One of the first things to establish is responsibility.
Your agency should know who serves in the applicable CJIS security roles and who is responsible for maintaining policies, coordinating with DPS, managing access, and responding to findings.
For a small department, several responsibilities may fall on the same person.
That's okay.
What's dangerous is when everyone assumes somebody else is doing it.
Have ready
- LASO designation/contact information
- TAC and other applicable CJIS role information
- Current agency contact information
- Internal responsibility assignments
- Escalation/contact information for IT or security providers
2. Build a CJIS policy folder
Don't wait until an audit to start hunting through shared drives.
Texas DPS provides sample policy templates covering areas including access control, awareness and training, auditing/accountability, configuration management, identification/authentication, incident response, maintenance, media protection, and personnel security. DPS specifically cautions agencies that templates are starting points that need to be customized and formally adopted—not used unchanged.
Create one location for your current policies and supporting procedures.
Depending on your agency and environment, your policy set may address areas such as:
- Access control
- Awareness and training
- Audit/accountability
- Configuration management
- Identification and authentication
- Incident response
- Maintenance
- Media protection
- Personnel security
- Physical/environmental protection
- System/communications protection
- Personally owned/mobile devices, where applicable
- Other policies required by your specific environment
The important test
Open each policy and ask:
Does this describe what our agency actually does?
Changing [AGENCY NAME] in a downloaded template isn't the same thing as implementing a policy.
3. Review every person who can access CJI
Create a list.
For each person, be prepared to determine:
- Who are they?
- Why do they need access?
- What systems can they access?
- What role/permissions do they have?
- Were applicable personnel-security requirements completed?
- Is required training current?
- Is the account still necessary?
Then look for the common problem:
People who no longer need access but still have it.
Employees leave. Dispatch arrangements change. Vendors change. People transfer jobs.
Your access list should change with them.
4. Check your training records
Don't merely ask:
Has everyone taken CJIS training?
Ask:
Can we prove it?
Maintain records showing applicable training and completion.
Texas DPS currently provides CJIS policy training resources in areas including incident response, access control, and identification/authentication.
Have ready
- Current personnel roster
- Training completion records
- Training dates
- Any applicable role-specific training
- Process for identifying upcoming expirations/retraining
A spreadsheet is better than memory.
5. Inventory the systems that touch CJI
Ask:
Where can CJI actually go in our agency?
Include more than the obvious desktop in dispatch.
Think about:
- RMS
- CAD
- mobile computers
- laptops
- tablets
- servers
- file shares
- backups
- printers
- removable media
- cloud services
- remote-access tools
- third-party integrations
- vendor support systems
For each system, identify:
| System | CJI? | Users | Location | Vendor/Owner | Authentication |
|---|---|---|---|---|---|
| RMS | |||||
| CAD | |||||
| Mobile | |||||
| File storage | |||||
| Other |
This inventory makes many of the other CJIS questions much easier to answer.
6. Check authentication and account management
For systems accessing CJI, verify the authentication controls applicable to your environment.
Review:
- Individual accounts
- Password/credential requirements
- MFA where required
- Account creation approval
- Account disabling
- Privileged/admin accounts
- Failed-login handling
- Session locking
- Remote access
- Periodic account review
Do not assume that because a vendor calls its product “CJIS compliant,” your agency's use of the product automatically satisfies every applicable requirement.
CJIS security is shared work.
7. Review physical security
CJIS doesn't exist only on servers.
Walk through your building as though you were seeing it for the first time.
Ask:
- Can visitors reach computers displaying CJI?
- Are workstations left unlocked?
- Where are printed criminal-history records placed?
- Who can enter secured areas?
- How are visitors handled?
- Are network/server areas appropriately controlled?
- What happens to discarded printed CJI?
- What happens to old hard drives or devices?
The FBI's guidance specifically addresses protection of both electronic and physical media containing CJI, including storage, transport, and destruction.
Have ready
- Physical-security procedures
- Visitor procedures/logs where applicable
- Media handling/destruction procedures
- Documentation of controlled areas as applicable
8. Know every vendor that could touch CJI
This is a particularly important one for smaller agencies because IT is frequently outsourced.
Think beyond the RMS vendor.
Potential vendors can include:
- managed IT provider
- cloud provider
- RMS/CAD vendor
- backup provider
- network contractor
- computer repair/support company
- dispatch provider
- integration vendor
Texas DPS says the CJIS Security Addendum is required for contractors/vendors with access to CJI and that contractor employees with such access must sign it before access is granted.
For each vendor, know
- What service do they provide?
- Can they access CJI?
- Can they access systems containing CJI?
- What agreements/addenda are required?
- Have applicable personnel requirements been completed?
- Where is information stored?
- How is access controlled?
- How are incidents reported to your agency?
- What happens when the relationship ends?
Keep the paperwork somewhere you can actually find it.
9. Have an incident-response plan before you have an incident
An incident-response plan answers:
What do we do when something goes wrong?
The current Texas audit policy requires an agency incident-response capability and plan, including defined responsibilities, reporting, review, and executive approval.
Your plan should be specific enough that someone can use it under pressure.
Know
- Who employees contact first
- Who evaluates/escalates the incident
- Who contacts DPS
- Who contacts IT/vendors
- How evidence is preserved
- How the incident is documented
- Who communicates externally if necessary
- How recovery occurs
- How the incident is reviewed afterward
Keep current contact information with the plan.
Texas DPS also publishes incident-response instructions and reporting resources; use the current DPS material rather than relying on an old copy saved locally.
10. Don't forget logs—and the evidence that someone reviews them
A system generating a log does not necessarily demonstrate that the agency is performing its required review or monitoring activity.
Identify:
- What is logged?
- Where are logs retained?
- Who has access?
- Who reviews them?
- How often?
- How is that review documented?
- What happens when something unusual is found?
The goal isn't to generate paperwork for its own sake.
It's to be able to show that the security process you say exists is actually happening.
11. Review mobile and remote access
Smaller departments increasingly work from:
- patrol vehicles
- laptops
- tablets
- phones
- remote locations
- home or administrative offices
For each method of remote/mobile access, ask:
- Is it authorized?
- Is the device agency-managed?
- How is the user authenticated?
- Is CJI stored locally?
- How is information encrypted?
- What happens if the device is lost?
- Can access be revoked remotely?
- Are personally owned devices permitted?
- If so, is there a documented policy?
The FBI specifically publishes guidance for personally owned devices accessing, processing, storing, or transmitting CJI.
12. Prepare an audit evidence folder
This may be the most actionable recommendation in the entire article.
Create a folder named CJIS Audit Readiness, then organize something like:
- 01 - Agency & CJIS Contacts
- 02 - Policies
- 03 - Personnel & Screening
- 04 - Training
- 05 - Access & Account Reviews
- 06 - System & Device Inventory
- 07 - Physical Security
- 08 - Vendors & CJIS Addenda
- 09 - Incident Response
- 10 - Audit & Security Logs
- 11 - Media & Disposal
- 12 - Network & System Documentation
- 13 - Prior Audit Findings
- 14 - Remediation Evidence
You don't necessarily need those exact folders.
The point is to move from:
I know we have that somewhere.
to:
Here is the evidence.
13. Review your previous findings
If the agency has been audited before, start there.
For every previous finding:
- What was the finding?
- What was changed?
- When was it changed?
- Who owns the corrected process?
- Is the correction still in place?
- Can you demonstrate it?
A corrective action from three years ago that quietly stopped happening is still a problem.
14. Do your own mock audit
Pick someone who wasn't responsible for assembling the documentation.
Have them ask:
- Show me your incident-response plan.
- Show me who has RMS access.
- Show me when those accounts were last reviewed.
- Show me CJIS training for Officer Smith.
- Show me your vendor's applicable CJIS documentation.
- Show me how a terminated employee loses access.
- Show me what happens to an old laptop.
- Show me your visitor procedures.
- Show me evidence that this recurring security review occurred.
Every time the answer begins with:
I think that's in…
write it down. That's what to fix before the real audit.
The one-page pre-audit checklist
Print this section and work through it before an auditor asks.
People
- CJIS roles identified
- Personnel roster reviewed
- Screening requirements documented
- Training current
- User access reviewed
- Former users removed
Policies
- Current policies collected
- Policies customized to agency
- Required approvals documented
- Required reviews documented
- Procedures match actual practice
Technology
- CJI systems inventoried
- Devices inventoried
- Authentication/MFA reviewed
- Remote access reviewed
- Patch/update processes documented
- Logging/monitoring reviewed
Physical & media
- Controlled areas reviewed
- Visitor procedures ready
- Printed CJI handling reviewed
- Media storage reviewed
- Media destruction documented
Vendors
- Vendors with potential CJI access identified
- Required agreements/addenda collected
- Vendor access reviewed
- Incident responsibilities understood
- Termination/offboarding procedures understood
Incident response
- Current plan available
- Roles assigned
- DPS/current external contacts verified
- Staff reporting procedure understood
- Evidence preservation addressed
- Plan review/testing documented as applicable
Audit evidence
- Training records
- Account/access records
- Review logs
- Vendor documentation
- System/network documentation
- Prior findings
- Remediation evidence
Don't aim to “pass the checklist”
The goal isn't to accumulate documents.
It's to be able to answer three questions:
Do we know how CJI is protected?
Are we actually doing what our policies say we do?
Can we demonstrate it?
If the answer to all three is yes, an audit becomes much less about scrambling for paperwork and much more about showing the security program your agency already operates.
Public-safety software should make security easier to explain.
- Thin Line builds public-safety systems around clear access controls, audit history, and the operational records agencies are responsible for protecting.