This guide contains everything you need to know about conducting an information security risk assessment questionnaire at your organization.
Isora GRC gives state and local agencies one connected workspace to conduct recurring Criminal Justice Information Services (CJIS) assessments and prepare for CJIS audits. In Isora, teams can customize and launch pre-built questionnaires across departments, assign owners to individual questions, and capture audit evidence alongside each response. They can even map CJIS policy areas to frameworks like NIST SP 800-53, so every finding traces back to the specific control requirement it satisfies.




























Most of the evidence a CJIS audit asks agencies to produce is spread across an assessment workbook, evidence in email and shared drives, and a separate exception tracker. When the CJIS Systems Agency samples a control and asks for the access reviews, training records, and exception approvals behind it, producing the answer can take hours of manual assembly. Even if the work is completed, the state or local agency can’t actually prove whether it’s compliant.
Launch structured assessments across departments, agencies, and vendors. Start from the prebuilt questionnaire library to assess CJIS policy areas 2 through 19 via the NIST SP 800-53 control families. Assign assessment questions to control owners who can attach documents and evidence to every response.
Turn any assessment response into findings that stay linked to questionnaires, security controls, frameworks, and IT assets. Assign ownership, score likelihood-and-impact, set remediation milestones, and track each risk, from identified to remediated. Record every change in an audit log to ensure total accountability and complete transparency.
Log every risk exception as a first-class record linked to assets, vendors, and applications. Attach justifications, approvers, compensating controls, and expiration dates. Set automated review reminders to renew or retire approved deviations so they don’t lapse into audit findings.
Generate reports and scorecards from assessments, risk register entries, tracked exceptions, and inventory records. Track completion rates and assessment scores by department or agency, with risk distribution and remediation progress all in one view. When an auditor asks whether a control is satisfied, trace its lineage from requirement to assessment question to response, with evidence attached. Then, simply export the report to PDF or CSV and deliver the audit package.
The CJIS Security Policy: What It Covers and What Changed The CJIS Security Policy is the FBI’s minimum security standard for protecting...
What Is CJIS? The FBI Division, the Security Policy, and What It Requires Criminal Justice Information Services (CJIS) is the FBI division that...
Third-Party Risk Management Frameworks: How to Build and Govern a TPRM Program A third-party risk management (TPRM) framework is the structure an...
TPRM Maturity Model: How to Score Third-Party Risk A TPRM maturity model is a self-assessment framework to score how developed a third-party risk...
NIST CSF vs Other Frameworks: Comparison Guide and Mapping Resources The NIST Cybersecurity Framework (CSF) is a voluntary, risk-based cybersecurity...
NIST 800-53 Vendor Management: How to Manage Third-Party Risk NIST 800-53 vendor management uses the NIST 800-53 System and Services Acquisition (SA)...
CJIS Security Policy v6.1 organizes its requirements into 20 policy areas. They cover access control, authentication, auditing, incident response, media protection, and personnel security, among others. Policy areas 2 through 19 correspond to the eighteen NIST SP 800-53 control families, with CJIS specifying its own parameter values. Requirements marked Existing or Priority 1 are sanctionable now. Priority 2 through 4 requirements come due September 30, 2027.
No. There is no FBI-issued organizational CJIS certification for any vendor to deliver. Agencies and their service providers are audited against the CJIS Security Policy by their state CJIS Systems Agency. Isora GRC supports that work by running the assessments and holding the evidence. It does not issue, confer, or guarantee any compliance outcome, and it is not an auditor, an assessor, or a CJIS Systems Agency.
No. CJIS policy areas 2 through 19 map to the eighteen NIST SP 800-53 control families, so the control families are shared ground. CJIS then prescribes specific values for parameters that NIST leaves organization-defined. Account lockout thresholds, session lock timeouts, and password comparison intervals are set by CJIS rather than chosen by the organization. An 800-53 program is a strong starting point, and the CJIS values still have to be assessed as CJIS states them.
The state CJIS Systems Agency runs the audit, typically on a three-year cycle, and the FBI CJIS Division audits the CSA itself. Since version 6.0, auditors sample operational evidence — access review records, training completion, exception approvals, log data — rather than reading policy documents. That shift is why an assessment record kept current between audits is worth more than one assembled at the end of the cycle.
No. The prebuilt questionnaire library covers NIST, CIS, HIPAA, GLBA, HECVAT, and CMMC. CJIS is not among them today. Agencies assess CJIS in Isora by bringing or building the control set their program uses. Many start from the 800-53 questionnaire, because policy areas 2 through 19 are the 800-53 families. Everything downstream — evidence capture, exception tracking, risk lineage, and reporting — works the same way it does for any framework.