What CJIS Means for an IT Provider

CJIS requirements affect more than the police officer or dispatcher directly accessing Criminal Justice Information.

Michigan specifically states that people with unescorted access to CJI — including IT staff and vendors — are subject to fingerprint-based background requirements. The Michigan Addendum also includes individuals responsible for configuring and maintaining systems and networks with access to or containing CJI within its concept of access.

That means ordinary IT responsibilities may need to be approached differently in a CJIS-governed environment.

People & Access

Technicians supporting systems containing or providing access to CJI may themselves fall within personnel-screening and access requirements.

Access should therefore be based on legitimate responsibilities rather than giving every technician unrestricted access to every system.

Accounts & Authentication

User accounts, administrative privileges, MFA, credential handling, and employee offboarding all affect the security of the environment.

An ordinary employee account and an administrative account should not automatically have the same level of access.

Remote & On-Site Support

The fact that a technician can technically connect to a system does not mean every remote-support method or workflow is appropriate.

The system involved, technician authorization, authentication, customer requirements, and type of information being accessed all matter.

Maintenance & Documentation

Patching, configuration changes, workstation maintenance, network changes, and troubleshooting need to be performed without weakening the safeguards surrounding the environment.

Useful documentation also improves continuity while sensitive infrastructure information remains protected.

Computer Ties Is Vetted for Michigan CJIS-Governed Work

Michigan State Police operates a Statewide IT Vendor Program for IT vendors used by multiple agencies. MSP states that the program facilitates fingerprinting and background checks for vendor personnel and centralizes those records so participating agencies do not need to duplicate the vetting process.

Computer Ties is enrolled in Michigan’s Statewide IT Vendor Program and maintains CJIS-related workforce requirements across the company.

Every Computer Ties employee is subject to:

Name-based background screening

Fingerprint-based background screening through the Michigan State Police CJIS process

Annual CJIS Online Security Awareness Training

A signed CJIS Security Addendum

Role-appropriate access to customer systems

Customer confidentiality requirements

Controlled handling of sensitive technical information

Security-focused support procedures for governed environments

The FBI Security Addendum exists specifically to establish security responsibilities where private contractors support criminal-justice systems or receive connectivity to CJIS systems.

This is why describing Computer Ties simply as “CJIS certified” would actually be less accurate than explaining what we do.

CJIS is a security policy and operating framework, not a general certification program for managed IT providers.

Computer Ties instead maintains the screening, training, agreements, and operational practices required for the CJIS-governed work we perform in Michigan.

Microsoft 365 GCC in a CJIS-Governed Environment

For eligible government and public-safety organizations, the Microsoft 365 environment should be considered alongside workstations, accounts, networks, authentication, and other security controls.

Microsoft 365 Government Community Cloud (GCC) is specifically available to eligible federal, state, local, and tribal government organizations and to certain nongovernment entities handling regulated government information.

Microsoft documents GCC commitments that include U.S.-based customer-content storage, logical separation from commercial Office 365 customer content, screened personnel access to customer content, and support for criminal-justice-information requirements.

Computer Ties can help with:

Evaluating commercial Microsoft 365 versus GCC

Confirming government-cloud eligibility requirements

Planning commercial-to-GCC migrations

Microsoft 365 government licensing guidance

User and mailbox administration

Multi-factor authentication

Administrative roles and permissions

Ongoing GCC tenant support

Microsoft 365 GCC can provide an important technology foundation for an organization subject to government requirements.

It does not, however, replace the organization’s responsibilities around employee access, endpoints, networks, training, policies, remote support, documentation, physical safeguards, or other required controls.

Where substantially more restrictive requirements apply — particularly certain CUI, ITAR, or defense-related workloads — GCC High may need to be evaluated separately.

Frequently Asked Questions

Is there such a thing as a CJIS-certified IT company?

There is no general FBI-issued CJIS certification for managed IT providers comparable to certifications such as SOC 2 or a professional license.

CJIS is centered on the FBI CJIS Security Policy and the requirements governing agencies, systems, personnel, contractors, access, and protection of Criminal Justice Information.

Vendors working within those environments must meet the requirements applicable to their role rather than simply obtaining a universal “CJIS-certified vendor” badge.

Is Computer Ties approved to support CJIS environments in Michigan?

Computer Ties is enrolled in Michigan’s Statewide IT Vendor Program and maintains the personnel screening, fingerprinting, training, Security Addendum, and support practices associated with its work in CJIS-governed environments.

Michigan State Police maintains this program for IT vendors serving multiple agencies and uses it to facilitate and centralize vendor personnel background-vetting records.

What CJIS-related requirements do Computer Ties employees complete?

Every Computer Ties employee undergoes both name-based and fingerprint-based background screening.

Employees also complete annual CJIS Online Security Awareness Training and have signed CJIS Security Addendums.

These requirements apply across the Computer Ties workforce rather than to only one designated government technician.

Does using an approved IT vendor make an agency compliant?

No.

The IT provider is only one part of the environment.

The agency remains responsible for applicable policies, users, training, physical safeguards, technical controls, agreements, systems, access decisions, and other CJIS requirements.

Does Computer Ties support environments where LEIN requirements apply?

Yes.

Computer Ties has experience supporting Michigan public-safety technology environments where LEIN and CJIS requirements affect system access, authentication, administration, maintenance, and support procedures.

Is Microsoft 365 GCC required for every CJIS environment?

Not necessarily.

The correct Microsoft environment depends on the organization, information being handled, systems, agreements, and applicable requirements.

Computer Ties can help determine whether GCC should be evaluated.

Does Microsoft 365 GCC automatically make an agency CJIS compliant?

No.

Microsoft 365 GCC includes government-specific commitments relevant to criminal-justice workloads, but the Microsoft tenant is only one component of the organization’s overall environment.

Can Computer Ties help implement MFA for a CJIS-governed environment?

Yes.

Computer Ties can help implement and administer MFA within supported systems while taking the requirements of the specific environment into account.

MFA strengthens authentication but does not replace the other required safeguards.

Can Computer Ties remotely support CJIS-governed systems?

Remote support can be appropriate when the technician, authentication method, access controls, affected systems, and customer requirements support it.

The remote-support process should be evaluated in context rather than assuming every commercial remote-support method is appropriate for every CJIS system.

Should ordinary users have administrator rights?

Administrative privileges should reflect legitimate job responsibilities rather than convenience.

Separating everyday user activity from elevated administrative access can reduce unnecessary privilege and aligns with sound security practice.

Work With an IT Provider Prepared for CJIS-Governed Environments

Government and public-safety organizations need an IT provider that understands that CJIS is more than a marketing label.

Computer Ties combines Michigan vendor-program participation, employee screening, fingerprint-based background checks, annual CJIS security-awareness training, signed Security Addendums, Microsoft 365 GCC experience, and security-focused IT practices to support qualifying government environments.

If your organization needs help with Microsoft 365 GCC, authentication, workstations, secure government networks, remote access, documentation, lifecycle planning, or broader public-safety IT support, start with a conversation.