Security built for state and local government
Keep a signed, reviewed record of every access on your own servers.
Controls
| Source | Control | Requirement | ARRTECH evidence |
|---|---|---|---|
| CJIS v6.1 | AU-2 | Log logons, access attempts and privileged actions. | AD, LDAP, VPN, database and Windows logs, classified into plain categories. → |
| AU-6 | Review audit records weekly. | Saved queries run as scheduled reports by email. → | |
| AU-9 | Protect audit information. | Signed, chained logs and role-based rights. → | |
| AU-11 | Retain audit records. | Retention set per source or group. → | |
| State law | Ohio R.C. 9.64 | Report within 7 and 30 days. | A case timeline with SLA tracking. → |
| Florida §282.3185 | Ransomware reported within 12 hours. | SOAR incidents with execution history. → | |
| Whole of state | Tenancy | Separation between agencies. | Tenants with their own users, sources, reports and alerts. → |
CJIS AU-6
Meet the CJIS weekly log review
The CJIS Security Policy requires reviewing audit records at least weekly (AU-6). ARRTECH sends scheduled reports, so every review has a date.
CJIS AU-9
Protect audit logs from change
CJIS control AU-9 requires protecting audit information from unauthorized change or deletion. ARRTECH signs every log as it is written.
Staffing
Respond with a small team
Many agencies run security with a handful of people. ARRTECH SOAR runs routine steps, and a person approves each decision.
Whole-of-state
Separate agencies on one platform
Statewide programs often protect many agencies at once. ARRTECH gives each agency its own data, rules and reports on one platform.
By rule
State law Ohio R.C. 9.64
Report within 7 and 30 days. ARRTECH: A case timeline with SLA tracking.
State law Florida §282.3185
Ransomware reported within 12 hours. ARRTECH: SOAR incidents with execution history.
Questions
Can a small team run it?
Yes. ARRTECH SOAR carries out response steps through your existing tools. Before it acts, a person gets up to five options by email and the playbook waits. The history shows who chose what and when.
Who can search the logs?
Each user sees only the sources they need, and the console records every sign-in, search and settings change.
Where does the data stay?
On Linux servers your agency operates, run by your own staff.
What stays with you?
Filing state reports, the CJIS Security Addendum for anyone with access, and the audit itself. The auditor assesses the agency, not the product.
Sources
Guide
What does the CJIS Security Policy require for logs?
The CJIS Security Policy requires logging access attempts (AU-2), weekly review (AU-6), protection (AU-9) and one year of retention (AU-11).
How often is a CJIS audit?
The FBI CJIS Audit Unit audits each state every three years, and states audit their local agencies.
Can state agencies share one security platform?
Yes. A multi-tenant platform keeps each agency’s data and reports separate.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.