# CJIS Compliance
The FBI CJIS Security Policy governs the lifecycle of criminal justice information (CJI), including access, authentication, agreements, dissemination, contractors, monitoring, incidents, and audits. The current source used here is version 6.0, dated December 27, 2024. (primary public record, [FBI CJIS Security Policy version 6.0](../../web%20archive/2026-08-10/le.fbi.gov/fbi-cjis-security-policy-version-6-0-dec-27-2024.md))
## Arkansas governance
12 CAR Part 5 provides that the Arkansas Crime Information Center system is administered by the ACIC Director under its Supervisory Board and identifies ACIC as Arkansas's control agency for NCIC and NLETS. This corrects the earlier shorthand that ASP “operates ACIC.” ACIC's official materials describe user agreements, audits, workstation controls, and secondary-dissemination records. (primary public record, [12 CAR Part 5](../../web%20archive/2026-08-10/webftp.blr.arkansas.gov/12-car-part-5-arkansas-crime-information-center-system.md)); (primary public record, [ACIC official history and terminal resources](../../web%20archive/2026-08-10/dps.arkansas.gov/acic-official-history-and-workstation-terminal-resources.md))
## How it appears in the corpus
- Conway onboarding required an ID, ORI, agency address, badge or identifier, and a video verification before enabling NCIC-derived hot-list sources ([[AR - Conway PD - Welcome to Flock! (3) - Flock Kickoff Slide Deck]], p. 15). This is a vendor onboarding control, not a completed CJIS audit.
- Flock told Conway that it operates consistently with CJIS requirements and works with agencies on audits ([[Flock Cameras Apr 2026 City Council QA Thread]]). That is a vendor assertion.
- ACIN materials describe AWS GovCloud, MFA, role-based access, logs, encryption, training, and vendor safeguards; the Peregrine addendum supplies contract requirements ([[ACIN Policy and Operations Manual]], pp. 13–21; [[Peregrine and Carahsoft Executed Contract]], pp. 20–23). These are policies and terms, not configuration evidence or completed assessments.
## CJI and platform-sharing boundary
CJIS requirements attach to CJI and to covered access, agreements, processing, and dissemination. Not every ALPR image, vendor metadata field, or sharing relationship is necessarily CJI. Conversely, a platform's cross-jurisdiction sharing is not categorically unconstrained merely because the vendor asserts CJIS compliance: the analysis must identify the data, source system, recipient, purpose, agreements, secondary dissemination, contractor role, and audit record. The corpus does not yet establish those facts for every Flock, ELSAG, or ACIN sharing path.
## Notes
Version 6.0, 12 CAR Part 5, and transaction-specific agreements control the current audit baseline. A slide, sales claim, or policy statement is evidence of an asserted safeguard, not proof that an operational deployment passed a CJIS or ACIC audit.