Working with public agencies across Oregon, we have noticed something: most municipalities are not struggling with CJIS compliance because they are ignoring it. They are struggling because there is often a real gap between what the paperwork says and how the agency actually runs day to day.
That gap has become harder to manage since the FBI released CJIS Security Policy v6.0, the most substantial update to the policy in its history. Auditors are no longer simply checking whether a control exists on paper. They are looking for evidence that it works consistently, across every person, device, and vendor that touches criminal justice data. For agencies that have been managing compliance at the documentation level, that shift changes a lot.
Below are the seven issues we see most consistently when working with Oregon municipal IT environments. They are common, operational, and all addressable.
Before We Get Into the Mistakes: What CJIS Compliance Actually Requires
The CJIS security policy exists to protect criminal justice information, arrest records, fingerprints, case files, biometric data, and surveillance footage across its entire lifecycle. It applies to every agency and vendor in that chain: police departments, courts, dispatch centers, and any technology partner whose systems interact with that data.
Non-compliance is not just a documentation issue. The FBI can restrict an agency's access to critical databases, and corrective action plans following audit findings are mandatory.
The 7 Mistakes
Mistake 01: Compliance Gets Treated as an Audit Preparation Exercise
One of the biggest problems municipalities still face is focusing on compliance only when an audit is approaching. Policies get reviewed once a year, password settings are updated temporarily, and documentation gets cleaned up before assessments, then normal habits return.
The problem is that the CJIS security policy is not designed around "audit week." It is meant to guide ongoing operational security. Compliance gaps usually happen quietly over time:
- Inactive accounts stay active long after an employee has left
- Access permissions expand beyond what a role actually requires
- Documented procedures and actual day-to-day practice slowly drift apart
- Departments begin handling processes differently without realizing it
Agencies that build routine compliance checkpoints into their regular operations tend to perform consistently better than those treating it as a once-a-year project.
Mistake 02: Shared Login Credentials Are Still Being Used
In some municipalities, teams continue sharing credentials for convenience, especially across older systems or departments with limited IT oversight. Shared logins create a serious accountability problem: if multiple people access the same system using one account, there is no clear way to track who accessed information or made changes.
Strong CJIS compliance depends heavily on individual accountability. The requirements are clear:
- Every person accessing criminal justice data must have their own individual account
- Access permissions must be tied to that person's specific role
- Accounts must be removed promptly when someone leaves the organization
This sounds straightforward, but many municipalities still struggle with it, especially when older systems, staffing shortages, or legacy workflows are involved.
Mistake 03: Older Technology Is Carrying More Risk Than It Appears To
Many Oregon municipalities are balancing modernization goals with tight budgets and aging infrastructure. As a result, public safety environments often still rely on outdated servers, unsupported operating systems, older VPN solutions, or fragmented networks built years ago. These systems still function, and that is precisely why the risk they carry tends to go unnoticed.
One of the biggest challenges with older infrastructure is that it becomes harder to support modern security controls. CJIS compliance requirements under v6.0 set specific standards around encryption, authentication, and system monitoring that older systems often cannot meet without significant changes. As vendor support ends, patching becomes inconsistent, and monitoring tools stop integrating properly.
A phased modernization plan, even one that moves incrementally over several years, gives an agency a defensible path forward, which is considerably better than documenting the risk and leaving it unaddressed.
Something Worth Acknowledging: Most of the gaps described here are not the result of agencies failing to take security seriously. They are the result of lean teams, constrained budgets, and systems that have grown more complex over time than any small IT department can reasonably manage alone.
Our CJIS compliance consulting work is designed for exactly this kind of environment: practical, realistic, and built around what Oregon municipalities can actually sustain.
Mistake 04: Migrating to Microsoft 365 Is Being Mistaken for Becoming Compliant
Many organizations assume that once they move to Microsoft 365, they are automatically aligned with compliance standards. But platforms alone do not create compliance. The way the environment is configured matters just as much as the technology itself.
In the CJIS compliance Oregon environments we have reviewed, the same governance gaps appear regularly:
- File-sharing settings that are open to external parties by default
- Former staff and contractor accounts that were never deactivated after departure
- Personal devices accessing organizational data with no management controls in place
- Audit logging is not configured to retain records for the period the policy requires
None of these are failures on Microsoft's part. They are the result of a migration being treated as the finish line rather than the starting point for ongoing governance.
Mistake 05: Vendor Access Is Given Quickly and Reviewed Rarely
Every municipality works with outside vendors, IT contractors, software providers, and support consultants, and most of those relationships begin with system access being granted to get a project started. What happens far less consistently is a review of that access once the project ends.
In many environments, old vendor accounts remain active, permissions that were expanded for a specific task never get adjusted back, and over time, no one on the agency side has a clear picture of who can access what. That creates unnecessary risk, especially when vendors interact with systems connected to criminal justice data.
Under CJIS compliance requirements, the responsibility for managing vendor access sits with the agency, not the vendor. A vendor access register reviewed on a regular schedule, rather than only when a new project begins, is one of the most practical steps an agency can take to close this gap.
Mistake 06: Security Training Is Fulfilling a Requirement Rather Than Building Real Awareness
Most municipal employees are not cybersecurity experts, and they should not be expected to be. But they do need practical awareness. A large share of security incidents still begin with very ordinary mistakes:
- Clicking on a phishing email that looked credible
- Reusing a weak password across multiple systems
- Accidentally sharing a sensitive file through an uncontrolled channel
- Not recognizing when a request or message looks suspicious
Unfortunately, many organizations still approach training as an annual formality rather than something integrated into daily operations. The strongest public-sector environments treat cybersecurity awareness as part of workplace culture, not compliance paperwork.
For municipalities working toward stronger CJIS compliance Oregon readiness, employee awareness remains one of the most important long-term investments.
Mistake 07: The Incident Response Plan Exists on Paper but Has Never Been Practiced
Almost every municipality has some form of incident response plan. What is much rarer is an agency that has actually walked its team through that plan in a structured exercise, and the difference between a plan that works and one that falls apart under pressure is almost always practice.
During a real incident, confusion becomes the biggest threat. The questions that need clear answers before an event, not during it, are
- Who responds first and makes the initial assessment?
- Who has the authority to isolate or take systems offline?
- Who communicates with leadership and on what timeline?
- Who coordinates with outside agencies or law enforcement?
As ransomware and public-sector cyber threats continue evolving, response planning has become a core part of responsible municipal operations. A tabletop exercise run once a year, where the team works through a realistic scenario together, is one of the most impactful steps an agency can take to improve actual readiness.
Final Thoughts
Most Oregon municipalities are making real progress toward stronger cybersecurity and operational resilience. But in 2026, many compliance gaps still come from operational inconsistencies rather than a lack of awareness.
Strong CJIS compliance is not about checking boxes once a year. It is about building reliable systems, consistent processes, and secure operational habits that can support public trust over the long term.
Working with PDX IT Strategy and Consulting
Our CJIS compliance consulting work is focused on access governance, vendor oversight, Microsoft 365 configuration, infrastructure planning, and incident response readiness, because that is where the real gaps tend to live.
If your agency is preparing for a CJIS audit or simply trying to get a clearer view of where your risks sit, reach out to our team for a consultation, straightforward, no obligation, and specific to your situation.
Frequently Asked Questions
What is CJIS compliance, and who does it apply to in Oregon?
It is the FBI's security standard for protecting criminal justice information. It applies to every Oregon agency and vendor that touches that data, police departments, courts, dispatch centers, and their IT providers, regardless of agency size.
What changed with CJIS Security Policy v6.0?
Auditors no longer just check whether a control exists; they look for evidence that it works consistently across all users, devices, and vendors. Full enforcement is required by October 2027.
What happens if an Oregon municipality fails a CJIS audit?
The FBI can restrict access to critical criminal justice databases and requires a mandatory corrective action plan. Repeated non-compliance can result in further operational restrictions.
Does moving to Microsoft 365 make our agency CJIS compliant?
No. M365 provides tools that can support compliance, but configuration, access governance, and audit logging still need to be set up and maintained by the agency.
How often should Oregon municipalities review vendor access?
At a minimum, quarterly, and any vendor account should be deactivated immediately when an engagement ends, not left open until the next review cycle.
What is the most practical first step for an agency unsure of its compliance status? A gap assessment against CJIS v6.0. It tells you exactly where your environment, processes, and documentation fall short and gives you a prioritized list of what to fix first.
PDX IT Strategy and Consulting is an Oregon-registered LLC serving municipalities, public utilities, and government agencies across the Pacific Northwest. Our team holds certifications including CEH, PMP, ITIL, and Six Sigma Black Belt.
