:

FBI'S CJIS V6.1 TIGHTENS ENCRYPTION AND SCANNING RULES

SECURITY DESK1 MIN READ
TUE, SEP 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The FBI's CJIS Security Policy v6.1 strengthens encryption requirements and vulnerability scanning mandates. Agencies must prepare for updated password, MFA, and identity verification standards ahead of compliance audits.

The latest version of the FBI's Criminal Justice Information Services (CJIS) security policy marks a shift toward continuous security assessment rather than periodic reviews. Key Changes: - Enhanced encryption standards across systems and data transmission - Mandatory vulnerability scanning frequency increases - Stricter password complexity and management requirements - Multi-factor authentication (MFA) expansion requirements - Enhanced identity and access control verification Security teams managing criminal justice data systems must prioritize these updates to maintain compliance. The continuous assessment model requires ongoing monitoring rather than relying on annual audits, fundamentally changing how agencies approach security operations. Organizations should audit current encryption implementations, review vulnerability scanning procedures, and assess MFA deployment across critical systems. The policy shift reflects evolving threat landscapes and the FBI's commitment to securing sensitive criminal justice information nationwide. Compliance deadlines and audit schedules vary by jurisdiction. Agencies should contact their CJIS liaisons for specific implementation timelines.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.

JUST NOWSecurity Desk

New research reveals that digital watermarks intended to protect content ownership are being repurposed as surveillance mechanisms to track user behavior and identify individuals across platforms.

2H AGOIndustry Desk

Donating or recycling an old laptop is environmentally responsible, but failing to erase your data first can expose personal information to new owners or data recovery specialists.

5H AGOIndustry Desk

BigCommerce has alerted merchants to a data breach stemming from compromised Ribon app credentials. Attackers used the stolen access to inject malicious scripts into online stores.

6H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.