Support ← All resources

CJIS compliance documentation

For U.S. agencies. Our policy and procedure set, written against the FBI CJIS Security Policy v6.1. Titles are listed here so you know what exists; the documents themselves are provided to agencies on request.

United States

Policy and procedure set

F4-CJIS-001
Continuous Monitoring Strategy
System-level continuous monitoring strategy and procedures for Smart Squad systems that process, store or transmit Criminal Justice Information.
F4-CJIS-002
Vulnerability and Patch Management
Policy and procedures for identifying, assessing, remediating and disclosing vulnerabilities in Smart Squad systems that process, store or transmit Criminal Justice Information.
F4-CJIS-003
Configuration Management Plan
Policy and procedures for baseline configuration, network topology, least functionality, authorized software and component inventory across Smart Squad systems handling Criminal Justice Information.
F4-CJIS-004
Authenticator Management and Credential Service Provider Statement
Faction Four's Credential Service Provider posture, authenticator lifecycle processes, records retention, and the digital identity acceptance statement covering restricted authenticators.
F4-CJIS-005
Risk Assessment Process and Register
How Faction Four identifies, assesses, records, treats and reviews risk to Criminal Justice Information — and the register of record.
F4-CJIS-006
Access Control and Separation of Duties
Separation of duties, the documented rationale for remote access, and retention of external system connection agreements.
F4-CJIS-007
Traffic Flow Policy and Exception Register
The traffic flow policy for each managed interface, and the register of documented exceptions with business need, duration and review.
F4-CJIS-008
System Monitoring and Information Integrity
Event detection and analysis, malicious code protection and false-positive handling, inbound and outbound traffic criteria, log provision, and response to unauthorized changes.
F4-CJIS-009
Incident Response Plan
Faction Four's incident response capability for Smart Squad systems that process, store or transmit Criminal Justice Information — preparation, detection, analysis, containment, eradication, recovery, reporting and post-incident review.
F4-CJIS-010
Physical and Environmental Protection
Physical and environmental controls for Smart Squad — inherited datacentre controls, Faction Four's own work areas, and the alternate work sites from which the platform is administered.
F4-CJIS-011
Security Awareness and Training
Literacy and role-based security and privacy training for Faction Four personnel with access to Criminal Justice Information, and the training records that evidence it.
F4-CJIS-012
System Maintenance
Controlled maintenance, maintenance tools, non-local maintenance and maintenance personnel for Smart Squad systems that process, store or transmit Criminal Justice Information.
F4-CJIS-013
Contingency Plan
Continuity and recovery of the Smart Squad service — essential functions, recovery objectives, alternate sites, backup, restoration and testing.
F4-CJIS-014
System and Services Acquisition
The Smart Squad development life cycle, developer configuration management, security testing, documentation and supplier management.
F4-CJIS-015
Personnel Security
Screening, transfer, termination and external personnel controls for Faction Four staff and contractors with access to Criminal Justice Information.
F4-CJIS-016
Media Protection
Access, marking, storage, transport, sanitisation and use restrictions for digital and non-digital media containing Criminal Justice Information.
F4-CJIS-017
Audit and Accountability
What Smart Squad records, what each record contains, how audit information is protected, reviewed and retained, and how it is provided to the agency.

System architecture

Supplied alongside the policy set, and usually the two documents an assessor asks for first.

F4-ARCH-018
Smart Squad — Cloud Architecture
The major components of a Faction Four hosted Smart Squad deployment on Microsoft Azure: how traffic reaches the application, where data is held and replicated, and what protects each tier.
F4-ARCH-019
Smart Squad — On-Premise Architecture
Component architecture, technology stack, deployment models, high availability and upgrade procedure for Smart Squad deployed in an agency's own data centre.

Nineteen documents in total. Each carries a version, an effective date, a named owner and approver, and a review cycle.

How to request them

Ask through any support channel and say which documents you need — or ask for the full set, which is the usual request. Include the agency name and who the documents are for, since we address the covering note to them.

What you receive. PDFs, in the agency edition — the same content, with internal engineering notes removed. Each is dated and version-stamped so you can tell what you are holding, and so can your assessor.

If your assessor needs something these do not cover, say so. We would rather answer the question than have you infer an answer from a document that was not written for it.

A note on scope

These documents describe Faction Four's controls — how Smart Squad is built, hosted, monitored and supported. CJIS compliance is shared: your agency holds obligations these documents do not speak to, such as personnel screening, physical security of your own facilities, and the terms of your CJIS Security Addendum.

Where a control is a joint responsibility, the documents say so and say which part is ours. If you are building a compliance matrix and want help mapping the boundary, ask — we have done it before and it is quicker with both sides in the room.