What you need to know
CJIS physical protection extends to transmission paths and output devices. Trace cable, closet, jack, monitor, printer, and other exposure beyond the room entrance.
Potentially affected
CJIS-scope facilities where criminal justice information traverses internal cabling, communications spaces, wall jacks, displays, printers, or other output devices.
DSE recommendation
Map every in-scope transmission and output point, assign physical protection and inspection controls, and test that unauthorized reach does not bypass the secure-area boundary.
Bottom line: a locked room does not protect a cable that leaves through an accessible ceiling, an active jack in a public area, or a display visible from outside the boundary. Physical scope follows the information path and output, not only the server-room door.
Source fact: CJIS policy addresses transmission paths and output devices
The FBI CJIS Security Policy v6.1 — PE-4 and PE-5, dated June 25, 2026, addresses physical protection for information-system distribution and transmission lines and devices. Its examples include locked wiring closets, locked or disconnected jacks, conduit or cable trays, and sensors for physical tampering. The policy also addresses controlling access to output from devices such as monitors and printers.
The examples reveal two separate exposure paths: connecting to or altering the transmission infrastructure, and observing or removing information after a legitimate system outputs it.
Source boundary and applicability
CJIS requirements apply based on the information, agency relationship, system and facility boundary, contracts, and direction from the responsible CJIS authority. The policy examples do not mandate the same physical measure for every cable or device, nor do they replace encryption, network access control, media protection, or personnel controls. A qualified assessment must select controls for the actual risk and architecture.
Applicability questions
- Where does in-scope information travel between secure endpoints, including shared risers and service spaces?
- Which patch panels, splices, jacks, converters, wireless bridges, and cabinets are physically reachable?
- Which displays, printers, scanners, removable media, and maintenance interfaces expose output?
- Are unused ports disconnected, blocked, authenticated, monitored, or otherwise controlled?
- Who may service each path, and how is work authorized and observed?
DSE recommendation: survey the complete physical information route
The following steps are DSE recommendations based on the cited source.
Overlay the logical data flow on a physical drawing showing rooms, ceilings, risers, closets, cabinets, wall plates, conduits, output devices, and public sight lines. Classify each point by reachability, information exposure, existing lock or enclosure, electronic protection, inspection frequency, and responsible owner. Remove or disable unnecessary paths through approved change control.
Test cabinet and closet access, unused jack state, tamper alert delivery where implemented, screen visibility, print collection, and service-person workflow. Coordinate with network, facilities, CJIS security, safety, and accessibility owners; physical protection must not create unapproved egress or maintenance hazards.
Verification and evidence
Retain the approved scope, sanitized route drawing, cable and output inventory, closet and cabinet access review, port-state evidence, tamper test, sight-line assessment, service logs, deficiency tickets, and periodic inspection results. Protect the detailed map because it can disclose sensitive facility and network information.
Official references
- FBI CJIS Security Policy v6.1 — PE-4 and PE-5 – Federal Bureau of Investigation; June 25, 2026
Review the official source
FBI CJIS Security Policy v6.1 — PE-4 and PE-5 · Published June 25, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE