HomeIntelligenceBrief
BREACH BRIEF 🟡 Medium Advisory

FBI Updates CJIS Security Policy to v6.1, Raising Encryption and Vulnerability Management Requirements

The FBI published CJIS Security Policy version 6.1, mandating 256‑bit encryption for CJI and monthly vulnerability scans. Organizations must adjust controls and evidence collection to stay audit‑ready, a scenario continuous control‑assurance programs are built to address.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 bleepingcomputer.com
🟡
Severity
Medium
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

FBI CJIS Security Policy v6.1 Raises Encryption Strength and Vulnerability Scan Frequency

What Happened – The FBI released CJIS Security Policy version 6.1 on June 25 2026. The update tightens cryptographic requirements (minimum 256‑bit keys for data in transit and at rest) and increases the mandated vulnerability‑scanning cadence from quarterly to monthly. It also clarifies audit‑priority phases, keeping Priority 1 controls sanctionable now while lower‑priority controls remain in “zero‑cycle” until Sept 2027.

Why It Matters for Trust & Control Assurance

  • Continuous control‑assurance programs must already capture evidence of encryption strength and monthly vulnerability scans to stay ahead of the new baseline.
  • Mapping the CJIS controls to the Verisq Common Framework (VCF) provides a single audit artifact that satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).
  • The Trust Center can automate collection of encryption‑configuration logs and scan‑report attestations, giving a defensible audit trail before the next sanction cycle.

Who Is Affected – Law‑enforcement agencies, state CJIS System Administrators, and any contractors handling Criminal Justice Information (CJI).

Recommended Actions

  1. Update encryption policies to require 256‑bit symmetric keys for all CJI in transit and at rest.
  2. Shift vulnerability‑management schedules to monthly scans and retain the reports as audit evidence.
  3. Verify your current audit phase with the relevant State CJIS System Agency and begin collecting continuous evidence in the Trust Center. Source: BleepingComputer

Technical Notes – The policy change does not introduce a new CVE; it amends existing control requirements (SC‑13, SC‑28) and the vulnerability‑management frequency. No new software or hardware is mandated, but organizations must ensure their cryptographic modules support 256‑bit keys and that scanning tools can run on a monthly cadence. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →