{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/",
        "slug": "protect-cjis-cabling-and-displays-beyond-the-secure-room-door",
        "url": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/"
        },
        "title": "Protect CJIS cabling and displays beyond the secure-room door",
        "summary": "CJIS physical protection extends to transmission paths and output devices. Trace cable, closet, jack, monitor, printer, and other exposure beyond the room entrance.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:44+00:00",
        "modified_at": "2026-08-25T21:36:17+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 2,
        "word_count": 434,
        "potentially_affected": "CJIS-scope facilities where criminal justice information traverses internal cabling, communications spaces, wall jacks, displays, printers, or other output devices.",
        "dse_recommendation": "Map every in-scope transmission and output point, assign physical protection and inspection controls, and test that unauthorized reach does not bypass the secure-area boundary.",
        "primary_source": {
            "name": "FBI CJIS Security Policy v6.1 — PE-4 and PE-5",
            "url": "https://le.fbi.gov/file-repository/cjis_security_policy_v6-1_20260625.pdf#page=209",
            "published_on": "2026-06-25",
            "authority": "le.fbi.gov"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> a locked room does not protect a cable that leaves through an accessible ceiling, an active jack in a public area, or a display visible from outside the boundary. Physical scope follows the information path and output, not only the server-room door.</p>\n<h2>Source fact: CJIS policy addresses transmission paths and output devices</h2>\n<p>The <a href=\"https://le.fbi.gov/file-repository/cjis_security_policy_v6-1_20260625.pdf#page=209\" target=\"_blank\" rel=\"noopener noreferrer\">FBI CJIS Security Policy v6.1 — PE-4 and PE-5</a>, dated June 25, 2026, addresses physical protection for information-system distribution and transmission lines and devices. Its examples include locked wiring closets, locked or disconnected jacks, conduit or cable trays, and sensors for physical tampering. The policy also addresses controlling access to output from devices such as monitors and printers.</p>\n<p>The examples reveal two separate exposure paths: connecting to or altering the transmission infrastructure, and observing or removing information after a legitimate system outputs it.</p>\n<h2>Source boundary and applicability</h2>\n<p>CJIS requirements apply based on the information, agency relationship, system and facility boundary, contracts, and direction from the responsible CJIS authority. The policy examples do not mandate the same physical measure for every cable or device, nor do they replace encryption, network access control, media protection, or personnel controls. A qualified assessment must select controls for the actual risk and architecture.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Where does in-scope information travel between secure endpoints, including shared risers and service spaces?</li>\n<li>Which patch panels, splices, jacks, converters, wireless bridges, and cabinets are physically reachable?</li>\n<li>Which displays, printers, scanners, removable media, and maintenance interfaces expose output?</li>\n<li>Are unused ports disconnected, blocked, authenticated, monitored, or otherwise controlled?</li>\n<li>Who may service each path, and how is work authorized and observed?</li>\n</ul>\n<h2>DSE recommendation: survey the complete physical information route</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<p>Overlay the logical data flow on a physical drawing showing rooms, ceilings, risers, closets, cabinets, wall plates, conduits, output devices, and public sight lines. Classify each point by reachability, information exposure, existing lock or enclosure, electronic protection, inspection frequency, and responsible owner. Remove or disable unnecessary paths through approved change control.</p>\n<p>Test cabinet and closet access, unused jack state, tamper alert delivery where implemented, screen visibility, print collection, and service-person workflow. Coordinate with network, facilities, CJIS security, safety, and accessibility owners; physical protection must not create unapproved egress or maintenance hazards.</p>\n<h2>Verification and evidence</h2>\n<p>Retain the approved scope, sanitized route drawing, cable and output inventory, closet and cabinet access review, port-state evidence, tamper test, sight-line assessment, service logs, deficiency tickets, and periodic inspection results. Protect the detailed map because it can disclose sensitive facility and network information.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://le.fbi.gov/file-repository/cjis_security_policy_v6-1_20260625.pdf#page=209\" target=\"_blank\" rel=\"noopener noreferrer\">FBI CJIS Security Policy v6.1 — PE-4 and PE-5</a> &#8211; Federal Bureau of Investigation; June 25, 2026</li>\n</ul>",
        "content_text": "Bottom line: a locked room does not protect a cable that leaves through an accessible ceiling, an active jack in a public area, or a display visible from outside the boundary. Physical scope follows the information path and output, not only the server-room door.\nSource fact: CJIS policy addresses transmission paths and output devices\nThe FBI CJIS Security Policy v6.1 — PE-4 and PE-5, dated June 25, 2026, addresses physical protection for information-system distribution and transmission lines and devices. Its examples include locked wiring closets, locked or disconnected jacks, conduit or cable trays, and sensors for physical tampering. The policy also addresses controlling access to output from devices such as monitors and printers.\nThe examples reveal two separate exposure paths: connecting to or altering the transmission infrastructure, and observing or removing information after a legitimate system outputs it.\nSource boundary and applicability\nCJIS requirements apply based on the information, agency relationship, system and facility boundary, contracts, and direction from the responsible CJIS authority. The policy examples do not mandate the same physical measure for every cable or device, nor do they replace encryption, network access control, media protection, or personnel controls. A qualified assessment must select controls for the actual risk and architecture.\nApplicability questions\n\nWhere does in-scope information travel between secure endpoints, including shared risers and service spaces?\nWhich patch panels, splices, jacks, converters, wireless bridges, and cabinets are physically reachable?\nWhich displays, printers, scanners, removable media, and maintenance interfaces expose output?\nAre unused ports disconnected, blocked, authenticated, monitored, or otherwise controlled?\nWho may service each path, and how is work authorized and observed?\n\nDSE recommendation: survey the complete physical information route\nThe following steps are DSE recommendations based on the cited source.\nOverlay the logical data flow on a physical drawing showing rooms, ceilings, risers, closets, cabinets, wall plates, conduits, output devices, and public sight lines. Classify each point by reachability, information exposure, existing lock or enclosure, electronic protection, inspection frequency, and responsible owner. Remove or disable unnecessary paths through approved change control.\nTest cabinet and closet access, unused jack state, tamper alert delivery where implemented, screen visibility, print collection, and service-person workflow. Coordinate with network, facilities, CJIS security, safety, and accessibility owners; physical protection must not create unapproved egress or maintenance hazards.\nVerification and evidence\nRetain the approved scope, sanitized route drawing, cable and output inventory, closet and cabinet access review, port-state evidence, tamper test, sight-line assessment, service logs, deficiency tickets, and periodic inspection results. Protect the detailed map because it can disclose sensitive facility and network information.\nOfficial references\n\nFBI CJIS Security Policy v6.1 — PE-4 and PE-5 – Federal Bureau of Investigation; June 25, 2026",
        "content_markdown": "Bottom line: a locked room does not protect a cable that leaves through an accessible ceiling, an active jack in a public area, or a display visible from outside the boundary. Physical scope follows the information path and output, not only the server-room door.\n\n## Source fact: CJIS policy addresses transmission paths and output devices\n\nThe [FBI CJIS Security Policy v6.1 — PE-4 and PE-5](https://le.fbi.gov/file-repository/cjis_security_policy_v6-1_20260625.pdf#page=209), dated June 25, 2026, addresses physical protection for information-system distribution and transmission lines and devices. Its examples include locked wiring closets, locked or disconnected jacks, conduit or cable trays, and sensors for physical tampering. The policy also addresses controlling access to output from devices such as monitors and printers.\n\nThe examples reveal two separate exposure paths: connecting to or altering the transmission infrastructure, and observing or removing information after a legitimate system outputs it.\n\n## Source boundary and applicability\n\nCJIS requirements apply based on the information, agency relationship, system and facility boundary, contracts, and direction from the responsible CJIS authority. The policy examples do not mandate the same physical measure for every cable or device, nor do they replace encryption, network access control, media protection, or personnel controls. A qualified assessment must select controls for the actual risk and architecture.\n\n## Applicability questions\n\n- Where does in-scope information travel between secure endpoints, including shared risers and service spaces?\n\n- Which patch panels, splices, jacks, converters, wireless bridges, and cabinets are physically reachable?\n\n- Which displays, printers, scanners, removable media, and maintenance interfaces expose output?\n\n- Are unused ports disconnected, blocked, authenticated, monitored, or otherwise controlled?\n\n- Who may service each path, and how is work authorized and observed?\n\n## DSE recommendation: survey the complete physical information route\n\nThe following steps are DSE recommendations based on the cited source.\n\nOverlay the logical data flow on a physical drawing showing rooms, ceilings, risers, closets, cabinets, wall plates, conduits, output devices, and public sight lines. Classify each point by reachability, information exposure, existing lock or enclosure, electronic protection, inspection frequency, and responsible owner. Remove or disable unnecessary paths through approved change control.\n\nTest cabinet and closet access, unused jack state, tamper alert delivery where implemented, screen visibility, print collection, and service-person workflow. Coordinate with network, facilities, CJIS security, safety, and accessibility owners; physical protection must not create unapproved egress or maintenance hazards.\n\n## Verification and evidence\n\nRetain the approved scope, sanitized route drawing, cable and output inventory, closet and cabinet access review, port-state evidence, tamper test, sight-line assessment, service logs, deficiency tickets, and periodic inspection results. Protect the detailed map because it can disclose sensitive facility and network information.\n\n## Official references\n\n- [FBI CJIS Security Policy v6.1 — PE-4 and PE-5](https://le.fbi.gov/file-repository/cjis_security_policy_v6-1_20260625.pdf#page=209) – Federal Bureau of Investigation; June 25, 2026"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/",
                "url": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Protect CJIS cabling and displays beyond the secure-room door",
                        "item": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/#article",
                "identifier": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/",
                "url": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/",
                "headline": "Protect CJIS cabling and displays beyond the secure-room door",
                "description": "CJIS physical protection extends to transmission paths and output devices. Trace cable, closet, jack, monitor, printer, and other exposure beyond the…",
                "abstract": "CJIS physical protection extends to transmission paths and output devices. Trace cable, closet, jack, monitor, printer, and other exposure beyond the room entrance.",
                "articleBody": "Bottom line: a locked room does not protect a cable that leaves through an accessible ceiling, an active jack in a public area, or a display visible from outside the boundary. Physical scope follows the information path and output, not only the server-room door.\nSource fact: CJIS policy addresses transmission paths and output devices\nThe FBI CJIS Security Policy v6.1 — PE-4 and PE-5, dated June 25, 2026, addresses physical protection for information-system distribution and transmission lines and devices. Its examples include locked wiring closets, locked or disconnected jacks, conduit or cable trays, and sensors for physical tampering. The policy also addresses controlling access to output from devices such as monitors and printers.\nThe examples reveal two separate exposure paths: connecting to or altering the transmission infrastructure, and observing or removing information after a legitimate system outputs it.\nSource boundary and applicability\nCJIS requirements apply based on the information, agency relationship, system and facility boundary, contracts, and direction from the responsible CJIS authority. The policy examples do not mandate the same physical measure for every cable or device, nor do they replace encryption, network access control, media protection, or personnel controls. A qualified assessment must select controls for the actual risk and architecture.\nApplicability questions\n\nWhere does in-scope information travel between secure endpoints, including shared risers and service spaces?\nWhich patch panels, splices, jacks, converters, wireless bridges, and cabinets are physically reachable?\nWhich displays, printers, scanners, removable media, and maintenance interfaces expose output?\nAre unused ports disconnected, blocked, authenticated, monitored, or otherwise controlled?\nWho may service each path, and how is work authorized and observed?\n\nDSE recommendation: survey the complete physical information route\nThe following steps are DSE recommendations based on the cited source.\nOverlay the logical data flow on a physical drawing showing rooms, ceilings, risers, closets, cabinets, wall plates, conduits, output devices, and public sight lines. Classify each point by reachability, information exposure, existing lock or enclosure, electronic protection, inspection frequency, and responsible owner. Remove or disable unnecessary paths through approved change control.\nTest cabinet and closet access, unused jack state, tamper alert delivery where implemented, screen visibility, print collection, and service-person workflow. Coordinate with network, facilities, CJIS security, safety, and accessibility owners; physical protection must not create unapproved egress or maintenance hazards.\nVerification and evidence\nRetain the approved scope, sanitized route drawing, cable and output inventory, closet and cabinet access review, port-state evidence, tamper test, sight-line assessment, service logs, deficiency tickets, and periodic inspection results. Protect the detailed map because it can disclose sensitive facility and network information.\nOfficial references\n\nFBI CJIS Security Policy v6.1 — PE-4 and PE-5 – Federal Bureau of Investigation; June 25, 2026",
                "datePublished": "2026-08-25T21:35:44+00:00",
                "dateModified": "2026-08-25T21:36:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/protect-cjis-cabling-and-displays-beyond-the-secure-room-door/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Protect CJIS cabling and displays beyond the secure-room door"
                },
                "articleSection": [
                    "Access Control",
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Access Control",
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Important priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 434,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "FBI CJIS Security Policy v6.1 — PE-4 and PE-5",
                    "url": "https://le.fbi.gov/file-repository/cjis_security_policy_v6-1_20260625.pdf#page=209",
                    "datePublished": "2026-06-25"
                }
            }
        ]
    }
}