
Suppose that your CJIS audit is on the calendar, but nobody knows who wrote the incident response plan sitting on a shared drive. People throughout the administration know the document exists, but not whether it satisfies anything specific to criminal justice information, or whether it is simply the countywide IT continuity plan with a CJIS label taped on the cover.
That uncertainty is common, and should be resolved before an auditor has the chance to spot it and start asking questions. Reviewers will ask for the plan, its distribution records, the exercise notes, and the completed reporting forms. An agency that cannot produce those artifacts may have a finding, regardless of how well its staff would follow the plan and respond to an incident.
Where Incident Response Sits in the Current Policy
The FBI CJIS Security Policy version 6.0, released in December 2024, reorganized the policy into 20 policy areas aligned with NIST Special Publication 800-53, revision 5. The FBI issued version 6.1 in June 2026 to incorporate the year’s policy changes, and the underlying control family structure carried forward unchanged.
Incident response, which sat inside Section 5.3, Policy Area 3, under version 5.9, now has its own control family, separate from the sections covering access control, audit logging, and personnel security. Agencies that have referenced the old Policy Area 3 numbering for years should expect the section references in their documentation to shift, even where the substance of the requirement has not.
When auditors will apply version 6.0 or 6.1 to a given agency’s next review is a separate question from when the FBI released it, and the answer varies by CJIS Systems Agency. Texas, for example, publishes its own schedule for when each policy version governs local audits. However, while Systems Agencies have some leeway, Priority 1 (P1) controls from newer policy versions can be immediately sanctionable.
Ultimately, auditors will assess whether a control is functionally implemented and fully documented, and should be less concerned about whether personnel can cite specific section numbers. An agency that maintains a comprehensive incident response plan, defined roles, testing records, and a structured reporting history is more likely to demonstrate compliance during a review, regardless of whether staff can identify the exact control family classification.
For the full breakdown, read our analysis of the move from version 5.9 to version 6.0.
What the Policy Actually Requires
Agencies still need a documented procedure for identifying, investigating, recording, and reporting significant incidents involving CJI to the CJIS Systems Agency, the affected criminal justice agency, and the FBI CJIS Division Information Security Officer.
An auditor will review that requirement in five distinct parts, outlined in the following table. While these elements do not represent the entirety of the policy’s requirements, they make up a central portion.
| Requirement | What It Means | Evidence Commonly Requested |
| A documented plan for CJI | Written and specific to CJI | The plan itself, dated and approved |
| Defined roles | Named responsibilities for who does what during an incident | Assignments that match the current staff roster |
| Distribution | The plan actually reaches the people who need it | Acknowledgment or receipt records |
| Testing | The plan has been exercised, not just filed away | Exercise records and after-action notes |
| Reporting path | Who gets notified, and how fast | Completed incident reporting forms |
Why a General IT Plan Is Not a CJI Plan
Most counties and municipalities already have an IT continuity or incident response plan covering the network, email system, and general fund software. That document usually does not name CJI, does not identify which systems inside the agency hold criminal history or offender data, and does not route a report to the CJIS Systems Agency or the FBI CJIS Division Information Security Officer. It usually routes to the county IT director and, eventually, to whoever handles the cyber insurance claim.
A plan specific to the CJIS Security Policy tells personnel what to do the moment they discover an incident, including who to contact (the CJIS Systems Agency, the affected criminal justice agency, and the FBI CJIS Division Information Security Officer), how to contact them, and when.
A plan that does not distinguish CJI incidents from ordinary IT incidents will not provide that notification path when someone needs it during a high-pressure, sensitive event.
What Reviewers Ask to See
In practice, a reviewer’s request list for this part of an audit tends to include the plan itself, records showing it reached the relevant staff, notes from at least one tabletop exercise or drill, and copies of any incident reports filed under the plan’s procedure.
A plan that lacks evidence it reached the right people, that those people read it, and that they have practiced the procedures is likely to result in a finding of noncompliance.
The FBI publishes sample forms that agencies can use. The User Rules of Behavior Acknowledgment Form explains the responsibilities of each user, including penalties. The Security Incident Response Form captures who reported an incident, when it happened, who was contacted, which systems were affected, and how it was resolved.
An agency that can point to completed versions of forms like these, or to internal forms that cover the same fields, creates a documentation trail every time an incident occurs. A reviewer will typically want to see evidence like that accumulating over time rather than being reconstructed the week before an audit.
How Turnover Creates the Gap
Many findings of noncompliance trace back to issues with staffing and turnover, not with the policies themselves or even how the staff will respond to an incident. Simply put, when people leave their positions, their knowledge goes with them.

This applies to a TAC (Terminal Agency Coordinator) or LASO (Local Agency Security Officer) who built the original plan and then retires or moves to another department. The next person inherits a binder or a shared drive folder without knowing its purpose.
And it also applies when the people named in a plan, who are supposed to be contacted, leave their posts. The roles on paper stop matching the actual roster, and nobody notices until an auditor asks who currently holds the positions listed in the plan.
A scheduled annual review is an important control that can catch these changes before a reviewer does.
Getting a Second Set of Eyes on Your Plan
Findings in this area rarely trace back to an actual security failure. More often, the documentation and the practice have simply fallen behind staffing changes and policy updates. A second set of eyes, especially from a team that knows what a reviewer asks for, can help you spot and close those gaps quickly.
At OpenFox, our CJIS Consulting practice is staffed by former state-level CJIS directors and agency leaders who have been on both sides of these reviews. They know which documents a reviewer often asks for first, and where agencies tend to have missing data.
The goal is to find where information is missing, and to provide it, long before an auditor enters your facility. Contact OpenFox to have a former state CJIS director review your incident response documentation ahead of your next CJIS audit.
