Mayer Networks

Government

CJIS-Focused Security

Agencies handling criminal justice information operate under the CJIS Security Policy. Mayer Networks supports those agencies by implementing and documenting technical controls, identity, access, encryption, logging, physical and network separation, in coordination with the agency and its state CJIS contacts.

Who this serves

  • Sheriff's departments and police departments
  • Courts and circuit clerks
  • Prosecutor and public defender offices
  • Agencies with access to state and federal criminal justice systems

What agencies run into

  • Uncertainty about which technical controls apply to which systems
  • Shared workstations and accounts in areas handling sensitive information
  • Remote access built before current requirements existed
  • Audit findings with no plan to resolve them

Scope of work

  • Review of technical controls against CJIS Security Policy areas
  • Advanced authentication and identity controls
  • Access control, logging and audit support
  • Encryption in transit and at rest where applicable
  • Network segmentation for criminal justice systems
  • Documentation to support audits
  • Personnel and vendor access considerations
  • Coordination with state CJIS and agency personnel

Authorized Personnel

Support for Restricted Government Environments

Some sheriff's offices, 911 centers and other public-safety agencies require background checks, agency approval or additional access controls before outside IT personnel are permitted to support their systems.

Mayer Networks works within those requirements and assigns appropriately authorized personnel where required. Our goal is to help agencies maintain tighter control over who can access sensitive systems while still providing the technical support those environments depend on.

  • Personnel background checks where required by the agency
  • Agency authorization before access is granted
  • Restricted access to sensitive systems
  • Role-based or least-privilege access
  • Controlled administrative credentials
  • Documentation of authorized support personnel
  • Department-specific security procedures
  • Removal of access when personnel no longer require it

How we work with an agency

  1. Step 1

    Scope

    Determine which systems, users and locations are in scope for criminal justice information.

  2. Step 2

    Review

    Compare implemented technical controls with applicable policy areas and document gaps.

  3. Step 3

    Remediate

    Implement controls in priority order with the agency's operational needs in mind.

  4. Step 4

    Document

    Maintain documentation the agency can present during audits.

We help translate requirements into technical action

Guidance rarely arrives as a work order. It arrives as a bulletin, a finding or a questionnaire, and somebody has to decide what it means for this county's actual systems. Mayer Networks acts as the technical resource alongside agency staff, within the scope the agency authorizes. We do not speak for any agency.

  1. 01

    What arrives

    An advisory, an audit finding, an insurer questionnaire, a state requirement or a vendor prerequisite.

  2. 02

    What it means here

    Which systems, users and buildings it touches in this specific environment.

  3. 03

    What it costs

    The technical work, the effort and where it fits against the fiscal year or a grant.

  4. 04

    What was done

    Implementation, then a written record the agency can present later.

What we implement, and where the compliance determination sits

The CJIS Security Policy translates into concrete technical work: advanced authentication for access to criminal justice information, encryption in transit and at rest, segmentation between criminal justice systems and general office traffic, auditing and log retention, physical access control at the places where equipment lives, and personnel screening handled by the agency. We implement the technical portions and document what was done, in the form an auditor will ask for.

What we do not do is issue a compliance verdict. Compliance determinations rest with the agency, its CJIS Systems Agency contacts and its auditors. Any provider claiming to certify an agency as CJIS compliant is describing something that does not exist, and agencies should treat that claim as a warning rather than a credential.

Third-Party Technology Access in Public-Safety Environments

Law enforcement and justice agencies run specialized applications, including records, jail, prosecution and imaging systems from vendors such as LAWMAN, ID Networks and Karpel. Those vendors periodically need remote access, upgrade assistance or infrastructure changes from the agency's IT provider.

Mayer Networks coordinates that work with the vendor and the agency, so access to criminal justice systems is deliberate, documented and limited to what the vendor's work requires. Access decisions rest with the agency and its CJIS contacts.

Government Software & Vendor Support

Why Mayer Networks

  • Direct experience supporting law enforcement and court environments
  • Technical controls implemented and documented, not just described
  • Coordination with agency personnel and state contacts
  • Responsive remote and onsite support from engineers based in Southern Illinois, not a queue in another time zone.

Security considerations

  • Advanced authentication for access to criminal justice information
  • Separation between criminal justice systems and general networks
  • Logging retained for audit purposes
  • Vendor access controlled and documented

Questions

Frequently asked questions

Still have a question? Call 618-529-4922 or send us the details.

Can Mayer Networks support CJIS environments?

Yes. We support agencies subject to the CJIS Security Policy by implementing and documenting applicable technical controls and coordinating with agency and state CJIS personnel.

Are you CJIS certified?

CJIS compliance is determined by the agency and the applicable CJIS Systems Agency, not by a vendor certificate. Personnel who support in-scope systems complete the required security awareness training and background screening processes as directed by the agency.

What does advanced authentication mean?

It is the CJIS requirement for an additional authentication factor beyond a username and password in defined circumstances. In practice this usually means multi-factor authentication.

Can criminal justice systems share our network?

In-scope systems require appropriate separation and controls. We design segmentation to meet those requirements while keeping the network manageable.

Industries that rely on this

References to government agencies and cybersecurity organizations describe Mayer Networks' experience coordinating with these entities on behalf of clients and do not imply endorsement, sponsorship, certification, or formal partnership unless expressly stated.

Let's talk about your technology

Tell us what you are running and what is not working. We will tell you plainly what we would do about it.