CJIS with ARRTECH

Records for your next CJIS audit.

Schedule a meeting

CJIS Security Policy v6.1 · Mapped Sep 24, 2026

Audit records for systems that touch criminal justice information

Log, monitor and respond as the Policy asks, and see plainly what stays with you.

Requirements

ClauseWhat it asksARRTECH
CJIS AU-2Event logging.Classified events. →
CJIS AU-9Audit information protected.A signature chain that breaks on change. →
CJIS SI-4System monitoring.MITRE-tagged events and correlation. →
CJIS IR-5Incidents tracked.Case records. →
CJIS MP-7Media use restricted.Device control. →

Scope

Know when the SIEM falls under the Policy

Logs that contain criminal justice information make the SIEM a system that processes it, with its own access, authentication and encryption requirements.

Logging

Record events in one form

ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.

Integrity

Prove nobody changed your logs

ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.

Incidents

Track every incident to its close

A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits.

Media

Control removable media

ARRTECH DLP device control allows or blocks any device class or specific device by vendor, product or serial number, per user or computer, with a manager approval option.

Limits

Know what stays with you

No ARRTECH product produces the record for these requirements.

CJIS IA-2

Multifactor authentication. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.

CJIS SC-13, SC-28

Validated cryptography and protection at rest. ARRTECH does not claim FIPS 140-3 validated cryptography. ARRTECH does not claim encryption at rest in its products.

CJIS Security Addendum

Screening and a signed addendum for anyone with access to CJI, including vendor support staff. Confirm the terms with us before deployment.

By rule

Naming a clause is not a claim of certification.

CJIS AU-2

Log the event types the Policy defines. ARRTECH: classification rules turn vendor codes into common event categories.

CJIS AU-9

Protect audit information from unauthorized access, modification and deletion. ARRTECH: a signature chain that breaks on change, and role-based rights per log source.

CJIS SI-4

Monitor the system to detect attacks and indicators of attack. ARRTECH: classified events with MITRE ATT&CK columns and correlation across sources.

CJIS IR-5

Track and document incidents. ARRTECH: case records with type, severity, assignee and history.

CJIS MP-7

Restrict the use of system media. ARRTECH: device control by class, vendor, product or serial number.

Questions

Is ARRTECH CJIS certified?

There is no CJIS certification. Agencies and CSAs are audited against the Policy.

Does the SIEM fall under the Policy?

Yes, if its logs contain criminal justice information.

Can our assessor check the logs without ARRTECH?

Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.

Which version is mapped?

CJIS Security Policy v6.1, Jun 25, 2026, which supersedes v6.0.

Sources

Guide

What is the CJIS Security Policy?

The FBI policy for protecting criminal justice information wherever it is stored or processed.

Who is audited?

Agencies and CJIS Systems Agencies, with contractors bound through the CJIS Security Addendum.

What changed in v6.1?

Version 6.1, published Jun 25, 2026, supersedes v6.0.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.