FBI Releases CJIS Security Policy v6.1, Strengthens Encryption and Vulnerability Scanning Requirements
New policy mandates enhanced cryptographic standards, increased scanning frequency, and updated authentication controls for federal criminal justice systems

Key Takeaways
- FBI CJIS Security Policy v6.1 has been released, introducing new encryption and vulnerability scanning requirements.
- The policy updates affect password, MFA, and identity management controls for federal agencies.
- Non-compliance may impact audit results and access to criminal justice information.
- No known exploitation of the policy changes; the update is a preventive regulatory measure.
Related Security News

Token Security Warns SOC 2 Controls May Fail to Distinguish AI Agent Activity from Human Actions
A recent advisory from Token Security argues that existing SOC 2 compliance frameworks are ill-equipped to differentiate between actions performed by AI agents using human credentials and legitimate human activity. This gap creates blind spots in access governance and anomaly detection for SOC 2-audited organizations. The report recommends framework adaptations, including agent identity governance and behavior-based anomaly detection, to maintain control effectiveness.




