Records & Digital Evidence Management for Law Enforcement: CJIS & Retention
Law enforcement records and digital evidence are governed primarily by the FBI CJIS Security Policy, now at version 6.0 (released December 27, 2024), plus chain-of-custody standards and state retention laws. Agencies must enforce multi-factor authentication, FIPS-validated encryption, 365-day audit logging, and defensible evidence handling to keep access to FBI systems.
For a police department or sheriff's office, managing records and digital evidence is no longer a filing-cabinet exercise — it is a cybersecurity and legal-defensibility problem. Two bodies of rules govern it. The FBI Criminal Justice Information Services (CJIS) Security Policy dictates how criminal justice information is stored, transmitted, and accessed. Chain-of-custody and retention standards decide whether digital evidence survives a defense challenge in court. Get either wrong and the consequences are concrete: lost access to national law enforcement databases, or evidence ruled inadmissible.
The stakes rose in December 2024, when the FBI released CJIS Security Policy version 6.0 and re-based the entire policy on the NIST SP 800-53 Revision 5 control catalog at the moderate baseline. At the same time, digital evidence — body-worn camera video, cellphone extractions, surveillance footage, interview recordings — has become central to the work. By one estimate, digital evidence now factors into roughly 90% of criminal cases. Records units and IT departments increasingly share responsibility for the same data and the same audit.
This guide is written for records managers, evidence custodians, and IT staff at municipal and county agencies, including the Lehigh Valley departments Reynolds Business Systems serves across Allentown, Bethlehem, and Easton. It covers what CJIS v6.0 actually requires, how to build a defensible chain of custody for digital evidence, how long body-worn camera footage must be kept, how to prepare for the triennial CJIS audit, and where agencies most often get this wrong.
What records and digital evidence management means in policing
Two categories of data sit at the center of every law enforcement records and IT program. The first is criminal justice information (CJI) — the data accessed through FBI systems such as the National Crime Information Center and the Interstate Identification Index, covering everything from wants and warrants to query results. The second is digital evidence: the electronic artifacts captured during an investigation. Both must be secured, both must be retained on a schedule, and both can be examined in an audit or a courtroom. The work of records management and the work of evidence integrity have converged.
Criminal justice information and its sensitive subset
Within CJI, Criminal History Record Information (CHRI) is a more sensitive subset whose access, use, and dissemination carry additional controls under both the CJIS Security Policy and 28 CFR Part 20. CHRI is the rap-sheet data that, mishandled, exposes an agency to the sharpest scrutiny, so a sound program treats it as a distinct tier with tighter access logging and dissemination tracking rather than lumping it in with general CJI.
Digital evidence is the other half of the picture, and its volume has reshaped investigations. With digital evidence a factor in an estimated 90% of criminal cases, an agency's ability to collect, preserve, and produce that evidence in a defensible form is no longer a specialty function — it is a core operational requirement that touches patrol, detectives, the evidence room, and IT.
- Criminal justice information (CJI), including query results from NCIC and the Interstate Identification Index
- Criminal History Record Information (CHRI), the sensitive subset governed additionally by 28 CFR Part 20
- Body-worn camera and in-car video
- Forensic images of phones, computers, and storage media
- Surveillance and third-party video, interview recordings, and case files
The FBI CJIS Security Policy: what it actually requires
The CJIS Security Policy is the binding security standard for any entity that accesses, stores, or transmits criminal justice information — not just police agencies, but the courts, dispatch centers, and private contractors that touch CJI on their behalf. It is the document a CJIS auditor measures an agency against, and it is the reason a records or IT decision that looks purely technical can carry legal weight.
The most important recent development is structural. On December 27, 2024, the FBI released CJIS Security Policy version 6.0 — the most significant restructuring of the policy in years. Version 6.0 maps the entire policy to NIST SP 800-53 Revision 5 at the moderate baseline, replacing the prior custom control structure with the same control catalog used across the federal government. For agencies, that means CJIS requirements now speak the same language as federal cybersecurity frameworks, which simplifies alignment but also raises the bar.
Practically, version 6.0 reorganizes CJIS requirements into 20 control families aligned with NIST 800-53 — among them Access Control, Identification and Authentication, and System and Communications Protection. This is a departure from the v5.9 era, when the policy organized requirements into 13 policy areas that agencies and their contractors evaluated. An agency that built its compliance documentation around the old 13 policy areas now has to re-map that work to the 20 control families, even where the underlying safeguards are largely the same.
The shift to NIST SP 800-53 is not cosmetic. Compliance evidence, policies, and self-assessments that were organized under the old 13 policy areas should be re-mapped to the 20 control families of v6.0 so that an auditor can trace each requirement to its control. Treat the re-mapping as a project, not a find-and-replace.
Retention varies widely
Body-worn-camera retention by state (days)
Authentication, encryption, access control, and logging
Beneath the structural change sit the technical safeguards that most directly affect day-to-day operations. Four of them — authentication, encryption, audit logging, and the personnel and incident controls that surround them — account for the bulk of what trips agencies up, and several carry hard dates.
Advanced authentication (multi-factor)
Multi-factor or advanced authentication for CJI access from outside a physically secure location is a P1 (priority-one) control, and it became subject to FBI CJIS sanctions on October 1, 2024. In plain terms, an officer pulling up CJI on a laptop in a patrol car, or a records clerk reaching it from a remote location, must authenticate with more than a password. This is the single requirement most likely to be tested first, and the one most agencies underestimate when they extend system access to mobile and remote users.
Encryption in transit and at rest
Under v6.0, CJI transmitted outside a physically secure location must be protected with FIPS 140-3 validated cryptographic modules. The policy requires AES encryption (FIPS 197) of at least 128-bit strength for criminal justice information moving outside secure locations, and it expects AES encryption at 256-bit strength for criminal justice information at rest. The validation matters as much as the algorithm: using AES is not enough if the cryptographic module is not FIPS-validated.
Audit logging
CJIS requires audit logs of CJI access events — including successful and unsuccessful authentication, permission changes, and privileged-account actions — to be retained for a minimum of 365 days (one year). An agency that logs access but purges the logs after 30 or 90 days fails this requirement even though it appears to be logging. The one-year floor is a common gap, because default retention settings on many systems fall well short of it.
Authentication and the most urgent controls are already enforced, but the remainder of v6.0 has a runway. Full compliance with the lower-priority P2 through P4 controls is required by September 30, 2027. Agencies should treat that date as the deadline to close the longer-tail items, not as permission to defer the P1 controls that are already enforceable.
| Safeguard | What v6.0 requires | Key date or value |
|---|---|---|
| Advanced authentication | Multi-factor authentication for CJI access from outside a physically secure location | P1 control, enforced via sanctions since October 1, 2024 |
| Encryption in transit | FIPS 140-3 validated modules; AES (FIPS 197) for CJI sent outside a secure location | At least 128-bit |
| Encryption at rest | AES encryption for stored criminal justice information | 256-bit expected |
| Audit logging | Log authentication successes/failures, permission changes, privileged actions | Retain a minimum of 365 days |
| Security awareness training | Train all personnel with CJI access, then refresh | Within 6 months of assignment; every 2 years |
| Incident reporting | Report security incidents to the CJIS Information Security Officer | Within 24 hours of discovery |
| Personnel screening | State and national fingerprint-based background checks for unescorted CJI access | Before access is granted |
| Full P2-P4 compliance | Implement the lower-priority control set under v6.0 | By September 30, 2027 |
Chain of custody for digital evidence
Where CJIS governs the security of information, chain of custody governs the credibility of evidence. NIST defines chain of custody as a process that tracks the movement of evidence through its collection, safeguarding, and analysis lifecycle by documenting each person who handled the evidence, the date and time it was collected or transferred, and the purpose for the transfer. For digital evidence, that documentation has to be as rigorous as it is for a physical item in a sealed bag, even though the artifact is a file that can be copied perfectly.
Preserving digital evidence well rests on a few non-negotiable practices. Secure handling requires write-blocking hardware to prevent any alteration of the original data, access-controlled storage, hash verification at each stage, and working from duplicate copies rather than the original. Hashing is the integrity anchor: best practice is to hash digital images and other evidence objects using a NIST-approved hashing algorithm such as SHA and store the resulting hashes separately in a secure location, so that a later hash can prove the file has not changed. If a file's hash still matches the value recorded at seizure, its integrity is demonstrable; if it does not, that is detectable.
The reason for the discipline is the courtroom. If the chain of custody is broken at any stage, digital evidence may be ruled inadmissible and the entire case may be dismissed. A gap of even a few hours in the custody record, an undocumented transfer, or work performed on an original instead of a duplicate can all become the thread a defense pulls.
A broken chain of custody can turn decisive digital evidence into nothing a court will hear.
- Who collected or received the evidence, with name and role
- The exact date and time of every collection and transfer
- The purpose of each transfer
- The hash value recorded at seizure and re-verified at each stage
- The storage location and the access controls applied to it
Building a CJIS and digital evidence compliance program, step by step
A defensible program is built deliberately. The sequence below folds the CJIS security controls and the evidence-handling discipline together, so that protection, retention, and proof reinforce one another rather than living in separate binders.
- Inventory the data and the systems. Identify every place CJI is stored, transmitted, or accessed, and every system that holds digital evidence — body-cam, in-car video, forensic images, case files — including mobile and remote access points.
- Re-map controls to v6.0. Translate existing compliance documentation from the old 13 policy areas to the 20 NIST 800-53 control families, so each requirement is traceable for an auditor.
- Enforce advanced authentication. Require multi-factor authentication for all CJI access from outside physically secure locations — the P1 control enforceable since October 1, 2024.
- Validate encryption. Confirm FIPS 140-3 validated modules, AES of at least 128-bit for CJI in transit outside secure locations, and AES 256-bit for CJI at rest.
- Set audit logging to retain at least 365 days. Log authentication successes and failures, permission changes, and privileged-account actions, and verify retention meets the one-year floor.
- Screen and train personnel. Complete state and national fingerprint-based background checks for everyone with unescorted CJI access, deliver security awareness training within six months of assignment, and refresh it every two years.
- Stand up incident response to the 24-hour clock. Build and rehearse a process to report security incidents to the CJIS Information Security Officer within 24 hours of discovery.
- Codify digital chain of custody. Standardize write-blocking, hashing with a NIST-approved algorithm, duplicate-only analysis, and a complete transfer log for every evidence item.
- Align retention schedules. Map body-cam and evidence retention to the applicable state and local requirements (see the next sections), and automate disposition so nothing is destroyed early or kept without basis.
- Operate on a calendar. Run the program continuously — refreshed training, current logs, scheduled disposition, and a standing readiness for the triennial audit.
Designate accountable owners for the two clocks that catch agencies off guard: the 24-hour incident-reporting deadline and the 365-day audit-log retention floor. Both are easy to meet with a process in place and easy to miss without one.
Worked example: a body-cam clip from stop to courtroom
The following scenario is illustrative. It combines the cited CJIS and chain-of-custody requirements with clearly hypothetical inputs to show how the obligations stack up for a single piece of digital evidence.
An officer in a hypothetical Lehigh Valley department records a traffic stop on a body-worn camera. At end of shift the file uploads to evidence storage, where the system computes a SHA hash and stores it separately — the integrity anchor. Because the recording captures a use-of-force incident, it is flagged as evidentiary and placed on a long retention hold rather than the agency's routine non-evidentiary window. When a detective later reviews the clip remotely, that access requires multi-factor authentication (enforced since October 1, 2024) and is recorded in an audit log retained for at least 365 days; the detective works from a duplicate, never the original. Each transfer — officer to evidence room, evidence room to detective, detective to the prosecutor — is logged with handler, date and time, and purpose, and the hash is re-verified at each step. At trial, the matching hash and the unbroken transfer record establish that the clip is what it purports to be and has not been altered. Had any link been missing, the same recording could have been challenged as inadmissible.
The example shows how the pieces interlock: the CJIS controls protect the access, the hash proves the integrity, and the transfer log proves the custody. No single one of them is sufficient on its own.
Body-worn camera and digital evidence retention schedules
Retention is where law enforcement records management gets jurisdiction-specific. There is no single national minimum for body-worn camera video; instead, states set their own floors, and they generally distinguish between non-evidentiary recordings (routine footage with no investigative value) and evidentiary recordings (use of force, arrests, or anything tied to a complaint). The difference in required retention between the two categories is often measured in years.
A few state frameworks illustrate the range. New Jersey requires body-worn camera recordings to be retained for not less than 180 days, with an automatic minimum three-year retention for recordings capturing use of force or that are the subject of a complaint. Michigan law requires evidentiary recordings to be retained for not less than 30 days, and not less than 3 years if the recording is relevant to a formal complaint against an officer or agency. California Penal Code 832.18 sets a minimum 60-day retention for non-evidentiary recordings and a minimum two-year retention for evidentiary recordings, while requiring that access and deletion logs be retained permanently. Across larger agencies generally, the Police Executive Research Forum reports that 60 to 90 days is a common non-evidentiary retention window, and many agencies retain non-evidentiary video for about 90 days.
| Jurisdiction / source | Non-evidentiary minimum | Evidentiary minimum |
|---|---|---|
| New Jersey (AG Directive 2021-5) | Not less than 180 days | At least 3 years for use-of-force or complaint recordings |
| Michigan (MCL 780.316) | Not less than 30 days | Not less than 3 years if relevant to a complaint against an officer or agency |
| California (Penal Code 832.18) | Minimum 60 days | Minimum 2 years; access and deletion logs kept permanently |
| Common large-agency practice (PERF) | About 90 days (60-90 days typical) | Held for the life of the case |
The non-evidentiary minimum is a floor, not a target. Once a recording becomes relevant to a complaint, a use-of-force review, or litigation, the short retention window no longer applies and the recording must be preserved for the longer evidentiary period — automating that reclassification prevents early deletion of footage that later turns out to matter.
CJIS audits and enforcement
CJIS compliance is not self-certified and forgotten. It is audited every three years (triennially) by the FBI CJIS Audit Unit or a delegated state-level CJIS Systems Agency. The triennial cycle means an agency should treat compliance as a standing condition rather than a project completed once and revisited only when the auditor schedules a visit. Documentation that is current — logs, training records, screening records, and the v6.0 control mapping — is what makes an audit routine instead of disruptive.
The consequences of failure are direct. Non-compliance with the CJIS Security Policy can result in termination of access to FBI CJIS systems, including the National Crime Information Center (NCIC), the Interstate Identification Index (III), and the National Instant Criminal Background Check System (NICS). For an operational agency, losing query access to those systems is not an administrative inconvenience; it degrades the ability to do core police work. That is why the security controls in this guide are best understood as operational continuity requirements, not just compliance line items.
| Control area | What the auditor verifies | Evidence to have ready |
|---|---|---|
| Authentication | MFA is enforced for CJI access outside secure locations | Identity and MFA configuration, access policies |
| Encryption | FIPS 140-3 modules; AES at required strengths in transit and at rest | Encryption settings and module validation records |
| Audit logging | Access events are logged and retained | Logs covering at least the prior 365 days |
| Personnel | Fingerprint screening and training are complete and current | Background-check records; training within 6 months and biennial refresh |
| Incident response | A process exists to report incidents to the ISO | Procedures and any reports filed within 24 hours |
| CHRI handling | Access to Criminal History Record Information follows 28 CFR Part 20 | Dissemination logs and access controls |
Where agencies get this wrong
The failures in this domain are predictable, and most come from treating one strong control as if it covered the whole program. The recurring patterns below are worth auditing against before an assessor does.
- Password-only remote access. Extending CJI access to laptops and mobile users without multi-factor authentication, despite the P1 control being enforceable since October 1, 2024.
- Short log retention. Logging access correctly but purging logs before the 365-day minimum, often because of default system settings.
- Algorithm without validation. Using AES but not FIPS 140-3 validated modules, which leaves encryption non-compliant even though it looks secure.
- Custody gaps. Working on original evidence instead of a duplicate, skipping hashing, or leaving undocumented transfers that can render evidence inadmissible.
- Stale training and screening. Letting security awareness training lapse past the two-year refresh, or granting unescorted CJI access before fingerprint-based background checks are complete.
- No incident clock. Lacking a rehearsed process to report incidents to the CJIS Information Security Officer within 24 hours of discovery.
- Manual retention. Relying on staff memory rather than automated schedules, which leads to evidentiary footage deleted at the non-evidentiary minimum.
- Treating the audit as the deadline. Preparing only before the triennial visit instead of operating in continuous compliance.
The Pennsylvania and Lehigh Valley angle
Pennsylvania agencies operate under the same federal CJIS Security Policy as every other state — the December 27, 2024 release of version 6.0, the NIST SP 800-53 mapping, the multi-factor authentication mandate, the 365-day audit-log floor, and the triennial audit all apply in the Commonwealth. The CJIS Systems Agency for Pennsylvania administers that compliance at the state level, and a municipal or county department in the Lehigh Valley answers to it just as a department elsewhere answers to its own state agency.
Records retention is where Pennsylvania specificity enters. Municipal and county records in Pennsylvania are governed by retention schedules administered through the Commonwealth's local-government records program and the Pennsylvania Historical and Museum Commission, and a department's retention of records and digital evidence must conform to the schedule that applies to it. Because no single statewide numeric body-camera retention floor is cited in this guide for Pennsylvania, agencies should confirm their obligations against their applicable Commonwealth and county schedules — and many look to neighboring benchmarks, such as New Jersey's not-less-than-180-day floor with a three-year minimum for use-of-force or complaint recordings, as a reference point for setting defensible windows.
Reynolds Business Systems is a family-owned records and document-management firm based in Emmaus, Pennsylvania, serving the Lehigh Valley — Allentown, Bethlehem, and Easton — and the broader Mid-Atlantic for more than 55 years. The federal and state rules in this guide are set by the FBI, NIST, and the Commonwealth; the operational work of meeting them — digitizing and organizing records, securing evidence storage, and structuring retention so disposition is defensible and an audit goes smoothly — is where a local records partner adds value. The role is not to interpret the law for an agency, but to make compliance dependable and auditable.
Frequently asked questions
What is the current version of the FBI CJIS Security Policy?
The current version is CJIS Security Policy 6.0, which the FBI released on December 27, 2024 — the most significant restructuring of the policy in years. Version 6.0 maps the entire policy to NIST SP 800-53 Revision 5 at the moderate baseline and reorganizes its requirements into 20 control families, replacing the custom structure and the 13 policy areas used in the v5.9 era.
Is multi-factor authentication required under CJIS today?
Yes. Multi-factor (advanced) authentication for criminal justice information access from outside a physically secure location is a P1 priority-one control, and it became subject to FBI CJIS sanctions on October 1, 2024. Any officer or staff member reaching CJI remotely or from a mobile device must authenticate with more than a password.
What is the deadline for full CJIS v6.0 compliance?
The highest-priority controls — including multi-factor authentication — are already enforced. Full compliance with the lower-priority P2 through P4 controls of CJIS v6.0 is required by September 30, 2027. Agencies should use that runway to close longer-tail items rather than to defer the P1 controls already enforceable.
How often is CJIS audited?
CJIS compliance is audited every three years (triennially), by the FBI CJIS Audit Unit or a delegated state-level CJIS Systems Agency. Because the cycle is recurring, agencies should maintain continuous compliance — current logs, training, screening, and control documentation — rather than preparing only ahead of a scheduled visit.
How long must CJIS audit logs be retained?
CJIS requires audit logs of CJI access events — successful and unsuccessful authentication, permission changes, and privileged-account actions — to be retained for a minimum of 365 days (one year). Default retention settings on many systems fall short of this, so the one-year floor is a frequent audit finding.
What is advanced authentication in CJIS?
Advanced authentication is CJIS's term for multi-factor authentication — verifying identity with more than just a password — when criminal justice information is accessed from outside a physically secure location. It is a P1 control that has been subject to FBI CJIS sanctions since October 1, 2024, and it is one of the requirements most commonly tested in an audit.
What encryption does CJIS require for criminal justice information?
Under v6.0, criminal justice information transmitted outside a physically secure location must be protected with FIPS 140-3 validated cryptographic modules, using AES encryption (FIPS 197) of at least 128-bit strength. For criminal justice information at rest, the policy expects AES encryption at 256-bit strength. Using AES is not sufficient on its own — the cryptographic module must be FIPS-validated.
What is chain of custody in digital forensics?
NIST defines chain of custody as a process that tracks the movement of evidence through its collection, safeguarding, and analysis lifecycle by documenting each person who handled the evidence, the date and time it was collected or transferred, and the purpose for the transfer. For digital evidence, that record must be as rigorous as for a physical item, even though the file can be copied perfectly.
What happens if the chain of custody is broken?
If the chain of custody is broken at any stage, digital evidence may be ruled inadmissible and the entire case may be dismissed. A gap in the custody record, an undocumented transfer, or analysis performed on an original instead of a duplicate can each become grounds for a defense challenge — which is why hashing, write-blocking, and complete transfer logs matter.
How long does law enforcement keep body-worn camera footage?
It varies by state and by whether the recording is evidentiary. New Jersey requires not less than 180 days, with at least three years for use-of-force or complaint recordings. Michigan requires not less than 30 days, and at least three years if relevant to a complaint. California requires a minimum of 60 days for non-evidentiary recordings and two years for evidentiary ones. Among larger agencies, 60 to 90 days is a common non-evidentiary window.
How is digital evidence collected and preserved?
Secure digital-evidence handling requires write-blocking hardware to prevent alteration of the original data, access-controlled storage, hash verification at each stage, and working from duplicate copies rather than the original. Best practice is to hash images and other evidence objects using a NIST-approved algorithm such as SHA and store the hashes separately in a secure location to prove integrity.
Who needs CJIS background checks and security training?
State and national fingerprint-based background checks are required for all personnel with unescorted access to criminal justice information. In addition, everyone with CJI access must complete CJIS security awareness training within six months of assignment and repeat it every two years (biennially). Lapsed training or access granted before screening is complete are common compliance gaps.
Sources Cited
20 REFS- Federal Bureau of Investigation (FBI), CJIS Division
- U.S. National Institute of Standards and Technology (NIST)
- U.S. National Institute of Standards and Technology (NIST)
- U.S. National Institute of Standards and Technology (NIST) / CNSSI 4009-2015
- National Institute of Justice (NIJ), U.S. Department of Justice
- Breach Craft
- Office of the Attorney General, State of New Jersey
- Michigan Legislature
- California State Legislature
- Brennan Center for Justice, NYU School of Law
- American Military University (AMU)
- Evidence Management Institute
- ACE Computers / Ace Forensics
- Forensic Science International: Digital Investigation (via PubMed Central, NIH/NLM)
- NiCE Public Safety & Justice



