FBI declares cloud vendors must meet CJIS security rules
- 08 February, 2012 07:54
- Comments
The FBI Tuesday reaffirmed its rule that all cloud products sold to to U.S. law enforcement agencies must comply with the FBI's Criminal Justice Information Systems (CJIS) security requirements.
While the nation's top law enforcement agency concedes that some vendors may have a tough time meeting those requirements, it insisted that there would be no compromising on security.
"The FBI remains committed to using technology in its information-sharing processes, but not at the sacrifice of the security of the information with which it has been entrusted," Stephen Fischer Jr., a spokesman for the FBI's CJIS division said today in an email to Computerworld.
Fischer's comments come less than two months after the Los Angeles Police Department canceled a planned migration to Google Apps because it said the cloud service was not compliant with CJIS security requirements.
At the time, two city officials noted that U.S. Department of Justice requirements for the CJIS are not currently compatible with cloud computing.
Google has also maintained that CJIS requirements are incompatible with cloud computing and therefore present a unique challenge to any cloud vendor.
The CJIS database, maintained by the FBI, is one of the world's largest repositories of criminal history records and fingerprints.
The records are available to law enforcement agencies and contractors around the country that comply with the security rules, which include requirements that all data, both in transit and at rest, be encrypted and that anyone who accesses the database pass FBI background checks.
Fischer today maintained that the CJIS security requirements are compatible with cloud computing.
"The CJIS Security Policy is a cloud-compatible policy," that was fully vetted and approved by local, state, tribal and federal law enforcement agencies in the U.S. and Canada, he said, while acknowledging that "the requirements may be tough for some vendors to meet."
One of the more challenging requirements requires cloud service providers to identify all system, database, security and network administrators who have access to criminal justice information, he said.
Similarly, cloud vendors will likely find it difficult to require fingerprint criminal background checks on all administrators with access to the criminal justice information. Fischer said.
Analysts have previously noted that large cloud vendors like Google that maintain staffed data centers outside the U.S.
Fischer noted as much today. "Admittedly, these requirements may be difficult for some cloud-computing vendors due to the sheer numbers and the geographic disbursement of their personnel," he said.
"However," he added, "these requirements aren't new to vendors serving the criminal justice community and many vendors have successfully met these requirements for years."
Jeff Gould, CEO of IT consulting firm Peerstone Research, said that the requirements are likely most challenging to large cloud providers with roots in the business of providing hosted services to consumers.
Several small, specialty providers, today offer cloud services that are compliant with CJIS requirements, said Gould, a co-founder of Safegov.org , which promotes best practices for deploying cloud-based systems in government entities.
Gould cited InterAct Public Safety, Datamaxx, and Vertical Computer Services as cloud companies that use secure data centers staffed by people who have undergone the requisite FBI background checks.
Services from such firms may be more expensive than the offerings from large vendors like Google, but these firms have invested the needed funds to meet the FBI's security requirements, he said.
He added that the FBI has tweaked CJIS requirements to make it easier for cloud vendors to comply.
"The old requirements were written before cloud computing took off," Gould said. "CJIS 5.0 goes out of its way to make room for cloud vendors."
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan , or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com .
Read more about cloud computing in Computerworld's Cloud Computing Topic Center.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Optimizing Storage and Protecting Data with Oracle Database 11g
This paper focuses on key Oracle Database 11g capabilities that help IT departments better optimise their storage infrastructure, enabling administrators to deliver a cost-effective, scalable data management platform that is easy to manage, reduces costs, and protects data while continuing to deliver the performance and availability that today’s businesses require. -
Oracle SOA vs. IBM SOA - Customer Perspectives on Evaluating Complexity and Business Value
The Service-Oriented Architecture (SOA) model has become the cornerstone of business computing. Its ability to greatly accelerate the development of business-critical applications promotes business agility, decreases time-to-value and total cost of ownership (TCO), and greatly increases the efficiency and strategic value of IT. SOA implementations tend to be complex, IT decision makers should carefully consider their choice of a SOA platform in terms of its ability to simplify the fundamental development, deployment, and management tasks involved. Read on. -
Best practices for implementing 2048-bit SSL
Secure sockets layer (SSL) technology continues to be essential to the growth of the web. With unabated increases in ecommerce traffic along with transmission of personal information, SSL is no longer just a nice to have capability; it is an absolute necessity. The requirement to protect information is further heightened by the universal availability of easy-touse hacking tools such as Firesheep. Read on.

















Comments
Post new comment