Purpose
The purpose of this document is to establish clear, consistent, and lawful operating policies for Criminal Intelligence Systems (CIS). These policies guide how intelligence is collected, stored, analyzed, and shared while protecting civil liberties, ensuring data integrity, and supporting lawenforcement objectives.
Scope
These policies apply to:
- All lawenforcement agencies that operate or access a CIS.
- Personnel with authorized access, including analysts, investigators, IT staff, and senior management.
- All data types processed by the system, from raw reports to derived analytical products.
Thirdparty vendors, contractors, and partners accessing the system must also comply with these policies under contractual agreements.
Core Principles
- Lawfulness: All activities must be authorized by applicable statutes, regulations, and judicial orders.
- Necessity & Proportionality: Data collection and analysis shall be limited to what is necessary to achieve a legitimate investigative purpose.
- Accuracy: Information entered into the CIS must be verified, current, and documented with source attribution.
- Confidentiality: Access is granted on a needtoknow basis, with rolebased permissions enforced.
- Integrity: Systems must have controls to prevent unauthorized modification or deletion of records.
- Accountability: Every action within the CIS is logged and traceable to an individual user.
- Transparency: Where legally permissible, policies and audit findings are made available to oversight bodies.
Roles & Responsibilities
| Role | Main Responsibilities |
|---|---|
| System Owner | Defines policy, approves changes, ensures resources, and oversees compliance. |
| Data Custodian | Manages data lifecycle, enforces retention schedules, and safeguards data integrity. |
| Analyst | Creates intelligence products, validates sources, and flags suspect data for review. |
| Investigator | Requests data, ensures lawful basis for collection, and documents investigative actions. |
| IT Security Officer | Implements technical controls, monitors for breaches, and conducts risk assessments. |
| Auditor / Oversight Officer | Performs periodic audits, reviews access logs, and reports findings to leadership. |
Key Procedures
1. Data Acquisition
All inbound data must be accompanied by:
- Legal authority (warrant, subpoena, or statutory provision).
- Source identification and reliability rating.
- Timestamp and method of collection.
2. Data Entry & Validation
Before entry, data are screened for:
- Duplication crosschecked against existing records.
- Relevance must support an ongoing investigation or strategic analysis.
- Quality errors are corrected, and uncertain items are flagged.
3. Access Control
Access is granted based on the principle of least privilege:
- Roles are mapped to permission sets in the system directory.
- Multifactor authentication (MFA) is mandatory for all remote access.
- Session timeouts after 15 minutes of inactivity.
4. Data Sharing
External sharing (e.g., with other agencies) follows a structured requestapproval workflow:
- Requestor submits a formal data request with justification.
- Data Custodian reviews the request for compliance with policy.
- Approved data are exported using encrypted formats and logged.
5. Retention & Disposal
Records are retained according to statutory periods (e.g., 5 years for standard intelligence, 10 years for terrorismrelated data). Disposal is performed via secure erasure or shredding of physical media, with a disposal certificate retained.
Security Controls
Technical safeguards include:
- Encryption at rest (AES256) and in transit (TLS1.3).
- Intrusion detection and prevention systems (IDPS) monitoring network traffic.
- Regular vulnerability scanning and patch management.
- Rolebased access control (RBAC) integrated with LDAP/Active Directory.
- Audit logging of every user action, immutable for at least 90 days.
Physical safeguards include restricted server rooms, badge access, and CCTV monitoring.
Compliance & Auditing
Compliance is measured against national statutes, such as the Criminal Justice Information Services (CJIS) Security Policy, and any relevant international agreements.
Internal Audits
Audits are conducted semiannually and cover:
- Access log review for unauthorized or suspicious activity.
- Verification of data accuracy against source documents.
- Assessment of adherence to retention schedules.
- Testing of backup and disasterrecovery procedures.
External Oversight
Independent oversight bodies (e.g., civilian review boards) receive summary audit reports annually. Any identified violations trigger corrective action plans within 30 days.
