[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnzLM48gm-O4CAJo34gjyJKx0D_dx8HOPyP0dl3ALqAE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"1455ff92-1c8a-41bc-af04-c15fe2710403","fbi-cjis-v61-raises-the-bar-on-encryption-and-vulnerability-scanning","d9b92925-a60c-404c-9dc8-f42151ddeacf","FBI CJIS v6.1 Raises the Bar on Encryption and Vulnerability Scanning","The FBI's updated CJIS Security Policy v6.1 introduces stricter requirements for encryption (256-bit for data in transit and at rest) and mandates monthly vulnerability scanning — a significant increase in frequency from prior guidance. Agencies that fail to align with these updated controls risk sanctions, as some requirements are already enforceable while others phase in through late 2027. This matters because criminal justice information is highly sensitive, and outdated encryption or infrequent scanning creates exploitable windows for threat actors. The shift toward continuous assessment signals that point-in-time audits are no longer sufficient for protecting this class of data. Organizations must treat compliance not as a checkbox exercise but as an ongoing operational discipline.","**Immediate actions:**\n- Audit all data-in-transit and data-at-rest encryption configurations to confirm 256-bit AES compliance across all systems handling CJI.\n- Schedule and automate monthly vulnerability scans for all assets within the CJIS security perimeter to meet the new frequency requirements.\n\n**Compliance & governance improvements:**\n- Map CJIS v6.1 control changes to your existing security program and assign owners with deadlines aligned to the 2027 phase-in schedule.\n- Establish a continuous compliance monitoring program that tracks control status in real time rather than relying solely on periodic audits.\n- Engage your CJIS Systems Agency (CSA) early to clarify which controls are currently sanctionable and prioritize remediation accordingly.\n\n**Detection & reporting measures:**\n- Implement centralized logging and SIEM alerting to detect configuration drift from CJIS-mandated baselines between audit cycles.\n- Conduct quarterly internal reviews of vulnerability scan results and remediation SLAs to demonstrate audit-readiness at any time.",[12,13,14,15,16,17,18,19,20],"CJIS Security Policy v6.1 — Section 5.10 (Encryption)","CJIS Security Policy v6.1 — Section 5.3 (Vulnerability Management)","NIST SP 800-53 Rev 5 — RA-5 (Vulnerability Monitoring and Scanning)","NIST SP 800-53 Rev 5 — SC-28 (Protection of Information at Rest)","NIST SP 800-53 Rev 5 — SC-8 (Transmission Confidentiality and Integrity)","CIS Control 7 — Continuous Vulnerability Management","CIS Control 3 — Data Protection","NIST CSF 2.0 — GV.OC (Organizational Context \u002F Compliance Obligations)","NIST SP 800-111 — Guide to Storage Encryption Technologies","published","2026-09-21T16:21:54.333567+00:00","2026-09-21T16:21:54.052+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ffbis-cjis-v61-what-security-teams-need-to-know\u002F","fbi-s-cjis-v6-1-what-security-teams-need-to-know-352d6a","FBI's CJIS v6.1: What Security Teams Need to Know.",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]