We’ve Updated Our Terms. We’ve updated our Terms Of ServicePrivacy Policy, and Data Processing Addendum, effective May 14, 2026. Please review the changes before continuing to use our services.

Compliance

How State and County Law Enforcement Use AccessPatrol to Meet CJIS and NIST 800-53 Requirements

How State and County Law Enforcement Use AccessPatrol to Meet CJIS and NIST 800-53 Requirements
Tony Lynn
Tony Lynn
Chief Operating Officer of CurrentWare
Updated on 5 min read
Share this article

The Data-Security Gap That No One Wants to Talk About

I spent nearly a decade in the U.S. Federal Government, including roles at the White House, the U.S. Department of Commerce, and the U.S. Senate. I later advised public sector clients on technology and strategic growth problems at Accenture. The same pattern showed up everywhere I went. Agencies invest in sophisticated network defenses. They architect robust identity programs and establish security operations centers, yet they often quietly overlook a glaring vulnerability: the unmonitored USB port on a standard workstation. It is the riskiest fragment of the environment, left entirely to chance.

For state police and county sheriffs, that gap matters more than almost anywhere else. The data moving across those endpoints is Criminal Justice Information (CJI): fingerprint records, NCIC queries, criminal histories, and investigative files. The rules governing that data just got a lot tougher.

What Changed with CJIS v6.0

The FBI released CJIS Security Policy v6.0 on December 27, 2024. It is the biggest update in over a decade. Industry analyses estimate the new version contains more than 180 primary controls and 1,300 subcontrols, all aligned to NIST 800-53 Rev. 5. Priority 1 controls are high priority and likely to draw closer audit attention. Full compliance is due October 1, 2027.

That sounds far away. It is not. The pressure points are clear: stronger Multi-Factor Authentication (MFA) for any environment touching CJI, removable media controls with real logging and encryption, endpoint configuration management, continuous monitoring with logs somebody actually reviews, and supply chain risk assessments for every technology acquisition.

The common thread is governance. CJIS v6.0 expects agencies to show that controls work over time, not just that they exist on paper.

What Nist 800-53 Expects at the Endpoint

Four NIST control families do most of the work on endpoint and removable media compliance:

NIST 800-53 Endpoint Control Families: MP, AC, AU, and SC

  • Media Protection (MP) covers the full lifecycle of any media holding or moving CJI. MP-7 specifically restricts how portable storage devices can be used.
  • System and Communications Protection (SC) governs how data moves and how it stays segmented, including boundaries and data at rest.
  • Access Control (AC) is the role-based and least-privilege layer. It includes which roles can read from or write to external devices.
  • Audit and Accountability (AU) requires every relevant endpoint event to be logged, protected from tampering, and kept long enough to be useful.

CurrentWare designed AccessPatrol to solve these types of architectural and governance challenges, as it can – block unauthorized peripherals, control who can read or write to external storage, log every transfer, and give assessors the artifacts they need.

Where AccessPatrol Fits

Three capabilities tend to close the gaps assessors flag most often.

NIST 800-53 Endpoint Control Families: MP, AC, AU, and SC

1. Device-level Enforcement

AccessPatrol uses allow and block lists across various storage and peripheral interfaces.. Agencies can approve specific encrypted devices by serial number or unique plug and play IDs and block everything else by default. That is the posture both CJIS v6.0 and NIST MP-7 point toward.

2. File Transfer logs Tied to Identity

Logs capture the user, the device, the file, the action, and the timestamp. They map directly to NIST AU-2 and AU-3, and they give you the evidence base for continuous monitoring under CA-7. Policy enforcement runs through Active Directory at the user and group level, which handles AC-3 and AC-6 at the endpoint.

3. Deployment That Fits the Environment

Architecture matters in law enforcement IT. Many state and county agencies run network enclaves that limit how endpoint telemetry can leave the environment, whether because of CJIS network segmentation, CSA guidance, or networks that were never built for cloud-first tools.

AccessPatrol supports a fully on-premise deployment, with the management console and database inside the agency’s environment. Cloud-based deployment is also possible for agencies whose architecture and policy allow it. Either way, the controls and the evidence trail look the same to an assessor.

Deploy Data Protection in Minutes, Not Weeks

Stop data loss from endpoints with AccessPatrol
Start Free TrialRequest a 20-minute walkthrough

Where to Start

Removable media is one of the rare CJIS gaps you can close quickly. A single deployment generates evidence across multiple control families at once. For a state police IT director or a county CIO deciding where to spend compliance budget, that is a strong place to begin.

CurrentWare specializes in helping state and local government agencies meet their security and compliance obligations, and we work with other agencies across the country on CJIS and NIST 800-53 readiness. That experience translates into faster deployments, cleaner audit evidence, and fewer surprises in the assessment cycle. If you are scoping an endpoint control project or preparing for an upcoming audit, I would welcome the conversation.

Frequently Asked Questions:

 

 

Full CJIS Security Policy v6.0 readiness is expected by October 1, 2027. However, while prior rules and controls under Priority 1 have been subject to sanctions for non-compliance, the greater modernization process allows for a “zero cycle” implementation of Priority 2, 3, and 4.

 

 

Keep reading

More articles
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Privacy Policy