BleepingComputer reports that the FBI’s CJIS Security Policy v6.1, published on June 25, 2026, further refines the modernization introduced in version 6.0, released on December 27, 2024. The policy remains aligned with NIST SP 800-53 and continues a shift toward more continuous security assessment.
The clearest technical changes concern encryption and vulnerability management. Under SC-13, encryption for CJI in transit outside physically secure locations now requires a symmetric cipher key with at least 256-bit strength, up from 128-bit in v6.0. SC-28 also specifies at least 256-bit encryption for CJI at rest outside physically secure locations. Vulnerability scanning must now occur at least monthly instead of quarterly.
Publication of v6.1 does not create one immediate audit baseline. Priority 1 controls have been sanctionable since October 1, 2024, while Priority 2, 3 and 4 controls remain in “zero-cycle” status until September 30, 2027. Texas is continuing audits against v5.9.5 through March 31, 2027. Verizon’s Data Breach Investigation Report found stolen credentials involved in 44.7% of breaches. Michigan State Police identified MFA among its top audit findings in October 2025, with Identification and Authentication controls scheduled for assessment during FY2027.
Comments
0No comments yet. Be the first to comment.