Audit records for systems that touch criminal justice information
Log, monitor and respond as the Policy asks, and see plainly what stays with you.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| CJIS AU-2 | Event logging. | Classified events. → |
| CJIS AU-9 | Audit information protected. | A signature chain that breaks on change. → |
| CJIS SI-4 | System monitoring. | MITRE-tagged events and correlation. → |
| CJIS IR-5 | Incidents tracked. | Case records. → |
| CJIS MP-7 | Media use restricted. | Device control. → |
Scope
Know when the SIEM falls under the Policy
Logs that contain criminal justice information make the SIEM a system that processes it, with its own access, authentication and encryption requirements.
Logging
Record events in one form
ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.
Integrity
Prove nobody changed your logs
ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.
Incidents
Track every incident to its close
A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits.
Media
Control removable media
ARRTECH DLP device control allows or blocks any device class or specific device by vendor, product or serial number, per user or computer, with a manager approval option.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
CJIS IA-2
Multifactor authentication. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.
CJIS SC-13, SC-28
Validated cryptography and protection at rest. ARRTECH does not claim FIPS 140-3 validated cryptography. ARRTECH does not claim encryption at rest in its products.
CJIS Security Addendum
Screening and a signed addendum for anyone with access to CJI, including vendor support staff. Confirm the terms with us before deployment.
By rule
Naming a clause is not a claim of certification.
CJIS AU-2
Log the event types the Policy defines. ARRTECH: classification rules turn vendor codes into common event categories.
CJIS AU-9
Protect audit information from unauthorized access, modification and deletion. ARRTECH: a signature chain that breaks on change, and role-based rights per log source.
CJIS SI-4
Monitor the system to detect attacks and indicators of attack. ARRTECH: classified events with MITRE ATT&CK columns and correlation across sources.
CJIS IR-5
Track and document incidents. ARRTECH: case records with type, severity, assignee and history.
CJIS MP-7
Restrict the use of system media. ARRTECH: device control by class, vendor, product or serial number.
Questions
Is ARRTECH CJIS certified?
There is no CJIS certification. Agencies and CSAs are audited against the Policy.
Does the SIEM fall under the Policy?
Yes, if its logs contain criminal justice information.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Which version is mapped?
CJIS Security Policy v6.1, Jun 25, 2026, which supersedes v6.0.
Sources
Guide
What is the CJIS Security Policy?
The FBI policy for protecting criminal justice information wherever it is stored or processed.
Who is audited?
Agencies and CJIS Systems Agencies, with contractors bound through the CJIS Security Addendum.
What changed in v6.1?
Version 6.1, published Jun 25, 2026, supersedes v6.0.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.