Organization Eligible To Access CJI Per CJIS Security Policy, v1.0

Defines conformance and assessment criteria for verifying that an organization is eligible to access CJI per the requirements of the CJIS Security Policy.
If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Steps (7)

1
NCJA Performs Criminal Justice Functions (NCJAPerformsCriminalJusticeFunctions)
Is the organization an NCJA that has been designated to perform criminal justice functions for a CJA??
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
2
NCJA Criminal Justice Functions Are Authorized (NCJACriminalJusticeFunctionsAreAuthorized)
Is the organization an NCJA that has been authorized to access CJI pursuant to Executive Order, statute, regulation, or inter-agency agreement?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
3
Channelers Performing Fingerprint Based Background Checks or Ancillary Functions (ChannelersPerformingFingerprintBasedBackgroundChecksorAncillaryFunctions)
Is the organization a channeler designated to request civil fingerprint-based background checks or noncriminal justice ancillary functions on behalf of a NCJA (public) or NCJA (private) for noncriminal justice functions?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
4
Contractor Performing Criminal Justice Functions (ContractorPerformingCriminalJusticeFunctions)
Is the organization a private contractor that has been designated to perform criminal justice functions for a CJA or NCJA?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
5
NCJA Performing Civil Fingerprint Background Checks (NCJAPerformingCivilFingerprintBackgroundChecks)
Is the organization a public or private NCJA designated to request civil fingerprint-based background checks, with the full consent of the individual to whom a background check is taking place, for noncriminal justice functions?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
6
Role Permitting Access to CJI Is Authorized (RolePermittingAccesstoCJIIsAuthorized)
Is the designation of the organization to perform functions that permit access to CJI authorized pursuant to federal law or state statute approved by the U.S. Attorney General?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
7
Organization Otherwise Authorized for CJI Access (OrganizationOtherwiseAuthorizedforCJIAccess)
Has the organization otherwise been deemed eligible for access to CJI per the requirements of the CJIS Security Policy?
Artifacts
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A2
Cite the specific clauses of the CJIS Security Policy satisfied, the determinining authority, and documentation of the determiniation
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (7)

C1
A NCJA (government) designated to perform criminal justice functions for a CJA shall be eligible for access to the CJI.
Citation
CJIS-SP-V5-4
Section 5.1.1.4.
C2
Access shall be permitted when such designation is authorized pursuant to Executive Order, statute, regulation, or inter-agency agreement.
Citation
CJIS-SP-V5-4
Section 5.1.1.4.
C6
Channelers designated to request civil fingerprint-based background checks or noncriminal justice ancillary functions on behalf of a NCJA (public) or NCJA (private) for noncriminal justice functions shall be eligible for access to CJI.
Citation
CJIS-SP-V5-4
Section 5.1.1.7.
C3
1. Private contractors designated to perform criminal justice functions for a CJA shall be eligible for access to CJI. 2. Private contractors designated to perform criminal justice functions on behalf of a NCJA (government) shall be eligible for access to CJI.
Citation
CJIS-SP-V5-4
Section 5.1.1.5.
C4
A NCJA (public) designated to request civil fingerprint-based background checks, with the full consent of the individual to whom a background check is taking place, for noncriminal justice functions, shall be eligible for access to CJI. A NCJA (private) designated to request civil fingerprint-based background checks, with the full consent of the individual to whom a background check is taking place, for noncriminal justice functions, shall be eligible for access to CJI.
Citation
CJIS-SP-V5-4
Section 5.1.1.6.
C5
Access shall be permitted when such designation is authorized pursuant to federal law or state statute approved by the U.S. Attorney General.
Citation
CJIS-SP-V5-4
Section 5.1.1.6, 5.1.1.7.
C7
Section 5.1.1 of the CJIS Security Policy addresses a number of ways an organization is eligible to access CJI.
Citation
CJIS-SP-V5-4
Section 5.1.1.