The FBI's CJIS Security Policy v6.1 introduces stricter requirements for encryption and vulnerability scanning, according to a BleepingComputer article. The update continues a broader move toward continuous security assessment rather than relying on point-in-time checks.

The policy affects state and local agencies that access criminal justice information. Security teams will need to address updated expectations around password policies, multi-factor authentication, and identity management to remain compliant.

The report, based on analysis from Specops, highlights that the changes are not just about meeting a checklist but about embedding ongoing monitoring into daily operations. Agencies should review their current security posture against the new requirements to avoid gaps in access control and data protection.