CJIS Security Policy 6.0 on Microsoft 365: auditing for criminal-justice agencies
Criminal-justice agencies and their vendors handle CJI under the CJIS Security Policy. Version 6.0 realigned it onto NIST SP 800-53 — which means the tenant checks you already run largely carry it. Here is the mapping.
Criminal-justice agencies and their vendors handle Criminal Justice Information (CJI) under the FBI's CJIS Security Policy. Version 6.0 realigned the policy onto NIST SP 800-53 identifiers, which is good news for anyone already auditing a Microsoft tenant against 800-53: the same control checks now read the same way. This is how CJIS maps onto Entra ID and Microsoft 365.
Why 6.0 changed the audit
Earlier CJIS policy used its own numbering. Version 6.0 aligns the requirements to the 800-53 control catalog, so the identity and access requirements now speak the language of AC, IA, AU and SC families. For an auditor, that means the Entra ID checks that satisfy NIST — MFA, least privilege, session control, logging — largely satisfy CJIS too, with CJIS-specific emphasis in a few areas.
The CJIS emphases that matter
- Advanced authentication — MFA is non-negotiable for access to CJI, including from within the agency network. Conditional Access plus phishing-resistant methods carry this.
- Personnel and access — access to CJI is tied to vetting; account management (AC-2) and least privilege (AC-6) map to joiner-mover-leaver hygiene and minimal privileged roles.
- Auditing and accountability — sign-in and audit logs retained and reviewable; CJIS has specific retention expectations that Entra ID log export must meet.
- Encryption — data in transit and at rest, which on the identity side means modern authentication only and no legacy protocols.
Shared responsibility. Microsoft's government cloud offerings can meet CJIS requirements at the platform level, but the tenant configuration is yours. A compliant platform with MFA gaps and open legacy authentication is not a compliant environment. The audit is about what you configured, not what the platform is capable of.
Evidence an assessor accepts
CJIS audits are conducted by the state's CJIS Systems Agency, and they want evidence, not assertions. A report that lists each control with its 800-53 identifier, the observed tenant setting and the remediation path gives the assessor exactly what they ask for — and gives you a defensible record between audits. Re-running the same baseline on a schedule turns the annual scramble into a continuous posture you can show at any time.
Related: FedRAMP on Microsoft 365 and CMMC and NIST SP 800-171.