
Personal devices improperly accessing criminal justice information (CJI) are among the most common findings in a CJIS audit, and personal mobile devices have been able to access that information since at least 2012. For mobile devices to access CJI and be compliant with CJIS Security Policy, certain conditions, which may be prohibitive, have to be met.
Here’s what the policy requires of a mobile deployment, where those requirements live in the current structure, what a defensible program looks like, and how a consultant can help you prepare for a CJIS audit.
Where Mobile Requirements Live in the Policy
Under CJIS Security Policy version 5.9, mobile devices sat in Policy Area 13, Section 5.13.
However, CJIS Security Policy version 6.0 reorganized the entire structure around 20 policy areas mapped to NIST Special Publication 800-53 Revision 5.
More recently, version 6.1 carried that structure forward. To better understand the how and why of these changes, you can review our analysis of the move from version 5.9 to version 6.0.
While versions 6.0 and 6.1 don’t substantively change the requirements for mobile devices accessing CJI, what has changed is where the requirements can be found in the policies. While mobile requirements still have a dedicated policy area, the newer NIST structure places related controls across other families that cover access control, configuration management, and system and communications protection, among others.
Practically, this means an IT director who goes looking for a single mobile chapter in the newer structure won’t find one. The requirements moved, though they didn’t disappear.
To complicate matters further, some agencies are still assessed against the 5.9 structure while their state works through the implementation timeline for the newer control areas. Agencies should confirm which version governs their agency’s current audit cycle before assuming where a requirement lives in their policies.
What the Policy Requires of a Managed Device
Whatever version applies to your agency, the underlying expectations for a managed mobile device have stayed consistent. The following table covers some of the fundamental mobile device management (MDM) expectations and capabilities laid out in the policy.
| Capability | What It Does | Why It Matters |
| Remote wipe | Clears a device, for example if it can’t be accounted for | Loss and theft are the common cases |
| Configuration lock | Prevents user-side changes | Settings can’t drift over time |
| Rooted device detection | Flags altered devices | Altered devices can’t touch CJI |
| Disk or folder encryption | Protects data at rest | Required to keep information secure |
| Patch enforcement | Blocks unpatched devices | Known gaps stay off the network |
None of these controls are exotic. But they can be difficult to implement on personal devices. Just as challenging can be the need to evidence that those controls exist on all of the personal devices in an agency.
Why Personal Phones Create the Biggest Gap

Officers checking agency systems from personal devices often bypass the agency’s management structure. These unmanaged devices typically lack remote wipe, configuration lock, and verifiable operating system versions and patches. In other words, these devices aren’t compliant with standard security protocols. Officers using personal devices risk their agency losing access to CJI.
A device that has been rooted or jailbroken can’t process, store, or transmit CJI at any time, and CJI may only move between authorized applications and storage areas on a device. A personal phone with no management profile can’t prove that it meets either condition.
What Reviewers Look For
A typical compliance audit opens with requests for the written mobile device policy, the device inventory, and evidence that the controls in that policy are enforced rather than only described.
While a policy document outlines intent, an auditor needs objective evidence of operational effectiveness. This can be demonstrated in a central management console that validates active enrollments, patch levels, and the detection of unauthorized device modifications (such as rooting or jailbreaking).
Log review standards apply to mobile endpoints the same way they apply to any other system that touches CJI. If your agency already reviews authentication and access logs as part of its standard audit procedure, you’ll want to confirm mobile application and connection sessions fall inside that review.
What a Compliant Mobile Program Looks Like
A defensible program combines a written policy that names the specific controls in force, a current device inventory, centralized management through an MDM or EMM (enterprise mobility management) platform, and a documented path for reporting a lost or stolen device.
A program that issues and enforces the use of agency-maintained devices is often simpler to defend during an audit than a program that permits personal devices. With agency-maintained devices, the agency controls enrollment from the start instead of retrofitting management onto a device an officer already owns and uses for personal purposes.
Encryption requirements apply even after an officer has left a physically secure location, which describes the normal operating environment for officers who work from patrol cars or at the scenes of incidents.
Agencies moving officers toward secure messaging and record access from the field, instead of an unmanaged workaround, typically standardize on a platform built for that purpose from the start. MessengerNow, for example, runs across desktops, tablets, and smartphones with encryption applied in transit and at rest, covering the storage and transmission requirements natively.
Reviewing Your Mobile Posture Before the Audit

Findings of noncompliance tied to mobile devices in a CJIS review usually relate to a failure to uniformly enforce centralized MDM controls across every device that accesses or stores CJI. The problems are usually operational and administrative rather than technical. The solution is to know which devices touch CJI, confirm that each is properly controlled, and have records.
At OpenFox, our CJIS Consulting practice is staffed by former state-level CJIS directors and agency leaders who have been on both sides of these reviews. They know which questions an auditor asks first and the kinds of documentation they want to see.
If your mobile device program has grown without a formal policy behind it, contact OpenFox for a review of your program before your next CJIS compliance audit.
