
A deep reference for records managers, evidence custodians, and IT staff in law enforcement: what FBI CJIS Security Policy v6.0 requires, how to build a defensible digital chain of custody, how long body-worn camera footage must be retained, and how to prepare for the triennial CJIS audit.
Guide briefing
Law enforcement records and digital evidence are governed primarily by the FBI CJIS Security Policy, now at version 6.0 (released December 27, 2024), plus chain-of-custody standards and state retention laws. Agencies must enforce multi-factor authentication, FIPS-validated encryption, 365-day audit logging, and defensible evidence handling to keep access to FBI systems.
More from the Compliance & Regulations category.
Next step
Share the framework, records condition, workflow, capacity issue, or implementation risk. Reynolds routes it to the discipline that owns the work — from Emmaus, with same-day response.
Need help applying this guide?
Talk to a specialistFor a police department or sheriff's office, managing records and digital evidence is no longer a filing-cabinet exercise — it is a cybersecurity and legal-defensibility problem. Two bodies of rules govern it. The FBI Criminal Justice Information Services (CJIS) Security Policy dictates how criminal justice information is stored, transmitted, and accessed. Chain-of-custody and retention standards decide whether digital evidence survives a defense challenge in court. Get either wrong and the consequences are concrete: lost access to national law enforcement databases, or evidence ruled inadmissible.
The stakes rose in December 2024, when the FBI released CJIS Security Policy version 6.0 and re-based the entire policy on the NIST SP 800-53 Revision 5 control catalog at the moderate baseline. At the same time, digital evidence — body-worn camera video, cellphone extractions, surveillance footage, interview recordings — has become central to the work. By one estimate, digital evidence now factors into roughly 90% of criminal cases. Records units and IT departments increasingly share responsibility for the same data and the same audit.
This guide is written for records managers, evidence custodians, and IT staff at municipal and county agencies, including the Lehigh Valley departments Reynolds Business Systems serves across Allentown, Bethlehem, and Easton. It covers what CJIS v6.0 actually requires, how to build a defensible chain of custody for digital evidence, how long body-worn camera footage must be kept, how to prepare for the triennial CJIS audit, and where agencies most often get this wrong.
Two categories of data sit at the center of every law enforcement records and IT program. The first is criminal justice information (CJI) — the data accessed through FBI systems such as the National Crime Information Center and the Interstate Identification Index, covering everything from wants and warrants to query results. The second is digital evidence: the electronic artifacts captured during an investigation. Both must be secured, both must be retained on a schedule, and both can be examined in an audit or a courtroom. The work of records management and the work of evidence integrity have converged.
Within CJI, Criminal History Record Information (CHRI) is a more sensitive subset whose access, use, and dissemination carry additional controls under both the CJIS Security Policy and 28 CFR Part 20. CHRI is the rap-sheet data that, mishandled, exposes an agency to the sharpest scrutiny, so a sound program treats it as a distinct tier with tighter access logging and dissemination tracking rather than lumping it in with general CJI.
Digital evidence is the other half of the picture, and its volume has reshaped investigations. With digital evidence a factor in an estimated 90% of criminal cases, an agency's ability to collect, preserve, and produce that evidence in a defensible form is no longer a specialty function — it is a core operational requirement that touches patrol, detectives, the evidence room, and IT.
The CJIS Security Policy is the binding security standard for any entity that accesses, stores, or transmits criminal justice information — not just police agencies, but the courts, dispatch centers, and private contractors that touch CJI on their behalf. It is the document a CJIS auditor measures an agency against, and it is the reason a records or IT decision that looks purely technical can carry legal weight.
The most important recent development is structural. On December 27, 2024, the FBI released CJIS Security Policy version 6.0 — the most significant restructuring of the policy in years. Version 6.0 maps the entire policy to NIST SP 800-53 Revision 5 at the moderate baseline, replacing the prior custom control structure with the same control catalog used across the federal government. For agencies, that means CJIS requirements now speak the same language as federal cybersecurity frameworks, which simplifies alignment but also raises the bar.
Practically, version 6.0 reorganizes CJIS requirements into 20 control families aligned with NIST 800-53 — among them Access Control, Identification and Authentication, and System and Communications Protection. This is a departure from the v5.9 era, when the policy organized requirements into 13 policy areas that agencies and their contractors evaluated. An agency that built its compliance documentation around the old 13 policy areas now has to re-map that work to the 20 control families, even where the underlying safeguards are largely the same.
The shift to NIST SP 800-53 is not cosmetic. Compliance evidence, policies, and self-assessments that were organized under the old 13 policy areas should be re-mapped to the 20 control families of v6.0 so that an auditor can trace each requirement to its control. Treat the re-mapping as a project, not a find-and-replace.
Retention varies widely
| Category | Value |
|---|---|
| Michigan | 30 |
| California | 60 |
| Common default | 90 |
| New Jersey | 180 |
Beneath the structural change sit the technical safeguards that most directly affect day-to-day operations. Four of them — authentication, encryption, audit logging, and the personnel and incident controls that surround them — account for the bulk of what trips agencies up, and several carry hard dates.
Multi-factor or advanced authentication for CJI access from outside a physically secure location is a P1 (priority-one) control, and it became subject to FBI CJIS sanctions on October 1, 2024. In plain terms, an officer pulling up CJI on a laptop in a patrol car, or a records clerk reaching it from a remote location, must authenticate with more than a password. This is the single requirement most likely to be tested first, and the one most agencies underestimate when they extend system access to mobile and remote users.
Under v6.0, CJI transmitted outside a physically secure location must be protected with FIPS 140-3 validated cryptographic modules. The policy requires AES encryption (FIPS 197) of at least 128-bit strength for criminal justice information moving outside secure locations, and it expects AES encryption at 256-bit strength for criminal justice information at rest. The validation matters as much as the algorithm: using AES is not enough if the cryptographic module is not FIPS-validated.
CJIS requires audit logs of CJI access events — including successful and unsuccessful authentication, permission changes, and privileged-account actions — to be retained for a minimum of 365 days (one year). An agency that logs access but purges the logs after 30 or 90 days fails this requirement even though it appears to be logging. The one-year floor is a common gap, because default retention settings on many systems fall well short of it.
Authentication and the most urgent controls are already enforced, but the remainder of v6.0 has a runway. Full compliance with the lower-priority P2 through P4 controls is required by September 30, 2027. Agencies should treat that date as the deadline to close the longer-tail items, not as permission to defer the P1 controls that are already enforceable.
| Safeguard | What v6.0 requires | Key date or value |
|---|---|---|
| Advanced authentication | Multi-factor authentication for CJI access from outside a physically secure location | P1 control, enforced via sanctions since October 1, 2024 |
| Encryption in transit | FIPS 140-3 validated modules; AES (FIPS 197) for CJI sent outside a secure location | At least 128-bit |
| Encryption at rest | AES encryption for stored criminal justice information | 256-bit expected |
| Audit logging | Log authentication successes/failures, permission changes, privileged actions | Retain a minimum of 365 days |
| Security awareness training | Train all personnel with CJI access, then refresh | Within 6 months of assignment; every 2 years |
| Incident reporting | Report security incidents to the CJIS Information Security Officer | Report suspected security incidents immediately, not to exceed one hour after discovery |
| Personnel screening | State and national fingerprint-based background checks for unescorted CJI access | Before access is granted |
| Full P2-P4 compliance | Implement the lower-priority control set under v6.0 | By September 30, 2027 |
Where CJIS governs the security of information, chain of custody governs the credibility of evidence. NIST defines chain of custody as a process that tracks the movement of evidence through its collection, safeguarding, and analysis lifecycle by documenting each person who handled the evidence, the date and time it was collected or transferred, and the purpose for the transfer. For digital evidence, that documentation has to be as rigorous as it is for a physical item in a sealed bag, even though the artifact is a file that can be copied perfectly.
Preserving digital evidence well rests on a few non-negotiable practices. Secure handling requires write-blocking hardware to prevent any alteration of the original data, access-controlled storage, hash verification at each stage, and working from duplicate copies rather than the original. Hashing is the integrity anchor: best practice is to hash digital images and other evidence objects using a NIST-approved hashing algorithm such as SHA and store the resulting hashes separately in a secure location, so that a later hash can prove the file has not changed. If a file's hash still matches the value recorded at seizure, its integrity is demonstrable; if it does not, that is detectable.
The reason for the discipline is the courtroom. If the chain of custody is broken at any stage, digital evidence may be ruled inadmissible and the entire case may be dismissed. A gap of even a few hours in the custody record, an undocumented transfer, or work performed on an original instead of a duplicate can all become the thread a defense pulls.
A broken chain of custody can turn decisive digital evidence into nothing a court will hear.
A defensible program is built deliberately. The sequence below folds the CJIS security controls and the evidence-handling discipline together, so that protection, retention, and proof reinforce one another rather than living in separate binders.
Designate accountable owners for the two clocks that catch agencies off guard: the 24-hour incident-reporting deadline and the 365-day audit-log retention floor. Both are easy to meet with a process in place and easy to miss without one.
The following scenario is illustrative. It combines the cited CJIS and chain-of-custody requirements with clearly hypothetical inputs to show how the obligations stack up for a single piece of digital evidence.
An officer in a hypothetical Lehigh Valley department records a traffic stop on a body-worn camera. At end of shift the file uploads to evidence storage, where the system computes a SHA hash and stores it separately — the integrity anchor. Because the recording captures a use-of-force incident, it is flagged as evidentiary and placed on a long retention hold rather than the agency's routine non-evidentiary window. When a detective later reviews the clip remotely, that access requires multi-factor authentication (enforced since October 1, 2024) and is recorded in an audit log retained for at least 365 days; the detective works from a duplicate, never the original. Each transfer — officer to evidence room, evidence room to detective, detective to the prosecutor — is logged with handler, date and time, and purpose, and the hash is re-verified at each step. At trial, the matching hash and the unbroken transfer record establish that the clip is what it purports to be and has not been altered. Had any link been missing, the same recording could have been challenged as inadmissible.
The example shows how the pieces interlock: the CJIS controls protect the access, the hash proves the integrity, and the transfer log proves the custody. No single one of them is sufficient on its own.
Retention is where law enforcement records management gets jurisdiction-specific. There is no single national minimum for body-worn camera video; instead, states set their own floors, and they generally distinguish between non-evidentiary recordings (routine footage with no investigative value) and evidentiary recordings (use of force, arrests, or anything tied to a complaint). The difference in required retention between the two categories is often measured in years.
A few state frameworks illustrate the range. New Jersey requires body-worn camera recordings to be retained for not less than 180 days, with an automatic minimum three-year retention for recordings capturing use of force or that are the subject of a complaint. Michigan law requires evidentiary recordings to be retained for not less than 30 days, and not less than 3 years if the recording is relevant to a formal complaint against an officer or agency. California Penal Code 832.18 sets a minimum 60-day retention for non-evidentiary recordings and a minimum two-year retention for evidentiary recordings, while requiring that access and deletion logs be retained permanently. Across larger agencies generally, the Police Executive Research Forum reports that 60 to 90 days is a common non-evidentiary retention window, and many agencies retain non-evidentiary video for about 90 days.
| Jurisdiction / source | Non-evidentiary minimum | Evidentiary minimum |
|---|---|---|
| New Jersey (AG Directive 2021-5) | Not less than 180 days | At least 3 years for use-of-force or complaint recordings |
| Michigan (MCL 780.316) | Not less than 30 days |
The non-evidentiary minimum is a floor, not a target. Once a recording becomes relevant to a complaint, a use-of-force review, or litigation, the short retention window no longer applies and the recording must be preserved for the longer evidentiary period — automating that reclassification prevents early deletion of footage that later turns out to matter.
CJIS compliance is not self-certified and forgotten. It is audited every three years (triennially) by the FBI CJIS Audit Unit or a delegated state-level CJIS Systems Agency. The triennial cycle means an agency should treat compliance as a standing condition rather than a project completed once and revisited only when the auditor schedules a visit. Documentation that is current — logs, training records, screening records, and the v6.0 control mapping — is what makes an audit routine instead of disruptive.
The consequences of failure are direct. Non-compliance with the CJIS Security Policy can result in termination of access to FBI CJIS systems, including the National Crime Information Center (NCIC), the Interstate Identification Index (III), and the National Instant Criminal Background Check System (NICS). For an operational agency, losing query access to those systems is not an administrative inconvenience; it degrades the ability to do core police work. That is why the security controls in this guide are best understood as operational continuity requirements, not just compliance line items.
| Control area | What the auditor verifies | Evidence to have ready |
|---|---|---|
| Authentication | MFA is enforced for CJI access outside secure locations | Identity and MFA configuration, access policies |
| Encryption | FIPS 140-3 modules; AES at required strengths in transit and at rest |
The failures in this domain are predictable, and most come from treating one strong control as if it covered the whole program. The recurring patterns below are worth auditing against before an assessor does.
Pennsylvania agencies operate under the same federal CJIS Security Policy as every other state — the December 27, 2024 release of version 6.0, the NIST SP 800-53 mapping, the multi-factor authentication mandate, the 365-day audit-log floor, and the triennial audit all apply in the Commonwealth. The CJIS Systems Agency for Pennsylvania administers that compliance at the state level, and a municipal or county department in the Lehigh Valley answers to it just as a department elsewhere answers to its own state agency.
Records retention is where Pennsylvania specificity enters. Municipal and county records in Pennsylvania are governed by retention schedules administered through the Commonwealth's local-government records program and the Pennsylvania Historical and Museum Commission, and a department's retention of records and digital evidence must conform to the schedule that applies to it. Because no single statewide numeric body-camera retention floor is cited in this guide for Pennsylvania, agencies should confirm their obligations against their applicable Commonwealth and county schedules — and many look to neighboring benchmarks, such as New Jersey's not-less-than-180-day floor with a three-year minimum for use-of-force or complaint recordings, as a reference point for setting defensible windows.
Reynolds Business Systems is a family-owned records and document-management firm based in Emmaus, Pennsylvania, serving the Lehigh Valley — Allentown, Bethlehem, and Easton — and the broader Mid-Atlantic for more than 55 years. The federal and state rules in this guide are set by the FBI, NIST, and the Commonwealth; the operational work of meeting them — digitizing and organizing records, securing evidence storage, and structuring retention so disposition is defensible and an audit goes smoothly — is where a local records partner adds value. The role is not to interpret the law for an agency, but to make compliance dependable and auditable.
The current version is CJIS Security Policy 6.0, which the FBI released on December 27, 2024 — the most significant restructuring of the policy in years. Version 6.0 maps the entire policy to NIST SP 800-53 Revision 5 at the moderate baseline and reorganizes its requirements into 20 control families, replacing the custom structure and the 13 policy areas used in the v5.9 era.
Yes. Multi-factor (advanced) authentication for criminal justice information access from outside a physically secure location is a P1 priority-one control, and it became subject to FBI CJIS sanctions on October 1, 2024. Any officer or staff member reaching CJI remotely or from a mobile device must authenticate with more than a password.
The highest-priority controls — including multi-factor authentication — are already enforced. Full compliance with the lower-priority P2 through P4 controls of CJIS v6.0 is required by September 30, 2027. Agencies should use that runway to close longer-tail items rather than to defer the P1 controls already enforceable.
CJIS compliance is audited every three years (triennially), by the FBI CJIS Audit Unit or a delegated state-level CJIS Systems Agency. Because the cycle is recurring, agencies should maintain continuous compliance — current logs, training, screening, and control documentation — rather than preparing only ahead of a scheduled visit.
CJIS requires audit logs of CJI access events — successful and unsuccessful authentication, permission changes, and privileged-account actions — to be retained for a minimum of 365 days (one year). Default retention settings on many systems fall short of this, so the one-year floor is a frequent audit finding.
Advanced authentication is CJIS's term for multi-factor authentication — verifying identity with more than just a password — when criminal justice information is accessed from outside a physically secure location. It is a P1 control that has been subject to FBI CJIS sanctions since October 1, 2024, and it is one of the requirements most commonly tested in an audit.
Under v6.0, criminal justice information transmitted outside a physically secure location must be protected with FIPS 140-3 validated cryptographic modules, using AES encryption (FIPS 197) of at least 128-bit strength. For criminal justice information at rest, the policy expects AES encryption at 256-bit strength. Using AES is not sufficient on its own — the cryptographic module must be FIPS-validated.
NIST defines chain of custody as a process that tracks the movement of evidence through its collection, safeguarding, and analysis lifecycle by documenting each person who handled the evidence, the date and time it was collected or transferred, and the purpose for the transfer. For digital evidence, that record must be as rigorous as for a physical item, even though the file can be copied perfectly.
If the chain of custody is broken at any stage, digital evidence may be ruled inadmissible and the entire case may be dismissed. A gap in the custody record, an undocumented transfer, or analysis performed on an original instead of a duplicate can each become grounds for a defense challenge — which is why hashing, write-blocking, and complete transfer logs matter.
It varies by state and by whether the recording is evidentiary. New Jersey requires not less than 180 days, with at least three years for use-of-force or complaint recordings. Michigan requires not less than 30 days, and at least three years if relevant to a complaint. California requires a minimum of 60 days for non-evidentiary recordings and two years for evidentiary ones. Among larger agencies, 60 to 90 days is a common non-evidentiary window.
Secure digital-evidence handling requires write-blocking hardware to prevent alteration of the original data, access-controlled storage, hash verification at each stage, and working from duplicate copies rather than the original. Best practice is to hash images and other evidence objects using a NIST-approved algorithm such as SHA and store the hashes separately in a secure location to prove integrity.
State and national fingerprint-based background checks are required for all personnel with unescorted access to criminal justice information. In addition, everyone with CJI access must complete CJIS security awareness training within six months of assignment and repeat it every two years (biennially). Lapsed training or access granted before screening is complete are common compliance gaps.
The current version is CJIS Security Policy 6.0, which the FBI released on December 27, 2024 — the most significant restructuring of the policy in years. Version 6.0 maps the entire policy to NIST SP 800-53 Revision 5 at the moderate baseline and reorganizes its requirements into 20 control families, replacing the custom structure and the 13 policy areas used in the v5.9 era.
Yes. Multi-factor (advanced) authentication for criminal justice information access from outside a physically secure location is a P1 priority-one control, and it became subject to FBI CJIS sanctions on October 1, 2024. Any officer or staff member reaching CJI remotely or from a mobile device must authenticate with more than a password.
The highest-priority controls — including multi-factor authentication — are already enforced. Full compliance with the lower-priority P2 through P4 controls of CJIS v6.0 is required by September 30, 2027. Agencies should use that runway to close longer-tail items rather than to defer the P1 controls already enforceable.
CJIS compliance is audited every three years (triennially), by the FBI CJIS Audit Unit or a delegated state-level CJIS Systems Agency. Because the cycle is recurring, agencies should maintain continuous compliance — current logs, training, screening, and control documentation — rather than preparing only ahead of a scheduled visit.
CJIS requires audit logs of CJI access events — successful and unsuccessful authentication, permission changes, and privileged-account actions — to be retained for a minimum of 365 days (one year). Default retention settings on many systems fall short of this, so the one-year floor is a frequent audit finding.
Advanced authentication is CJIS's term for multi-factor authentication — verifying identity with more than just a password — when criminal justice information is accessed from outside a physically secure location. It is a P1 control that has been subject to FBI CJIS sanctions since October 1, 2024, and it is one of the requirements most commonly tested in an audit.
Under v6.0, criminal justice information transmitted outside a physically secure location must be protected with FIPS 140-3 validated cryptographic modules, using AES encryption (FIPS 197) of at least 128-bit strength. For criminal justice information at rest, the policy expects AES encryption at 256-bit strength. Using AES is not sufficient on its own — the cryptographic module must be FIPS-validated.
NIST defines chain of custody as a process that tracks the movement of evidence through its collection, safeguarding, and analysis lifecycle by documenting each person who handled the evidence, the date and time it was collected or transferred, and the purpose for the transfer. For digital evidence, that record must be as rigorous as for a physical item, even though the file can be copied perfectly.
If the chain of custody is broken at any stage, digital evidence may be ruled inadmissible and the entire case may be dismissed. A gap in the custody record, an undocumented transfer, or analysis performed on an original instead of a duplicate can each become grounds for a defense challenge — which is why hashing, write-blocking, and complete transfer logs matter.
It varies by state and by whether the recording is evidentiary. New Jersey requires not less than 180 days, with at least three years for use-of-force or complaint recordings. Michigan requires not less than 30 days, and at least three years if relevant to a complaint. California requires a minimum of 60 days for non-evidentiary recordings and two years for evidentiary ones. Among larger agencies, 60 to 90 days is a common non-evidentiary window.
Secure digital-evidence handling requires write-blocking hardware to prevent alteration of the original data, access-controlled storage, hash verification at each stage, and working from duplicate copies rather than the original. Best practice is to hash images and other evidence objects using a NIST-approved algorithm such as SHA and store the hashes separately in a secure location to prove integrity.
State and national fingerprint-based background checks are required for all personnel with unescorted access to criminal justice information. In addition, everyone with CJI access must complete CJIS security awareness training within six months of assignment and repeat it every two years (biennially). Lapsed training or access granted before screening is complete are common compliance gaps.
| Not less than 3 years if relevant to a complaint against an officer or agency |
| California (Penal Code 832.18) | Minimum 60 days | Minimum 2 years; access and deletion logs kept permanently |
|---|
| Common large-agency practice (PERF) | About 90 days (60-90 days typical) | Held for the life of the case |
|---|
| Encryption settings and module validation records |
| Audit logging | Access events are logged and retained | Logs covering at least the prior 365 days |
|---|
| Personnel | Fingerprint screening and training are complete and current | Background-check records; training within 6 months and biennial refresh |
|---|
| Incident response | A process exists to report incidents to the ISO | Procedures for reporting suspected security incidents immediately, not to exceed one hour |
|---|
| CHRI handling | Access to Criminal History Record Information follows 28 CFR Part 20 | Dissemination logs and access controls |
|---|