What CJIS Means for an IT Provider
CJIS requirements affect more than the police officer or dispatcher directly accessing Criminal Justice Information.
Michigan specifically states that people with unescorted access to CJI — including IT staff and vendors — are subject to fingerprint-based background requirements. The Michigan Addendum also includes individuals responsible for configuring and maintaining systems and networks with access to or containing CJI within its concept of access.
That means ordinary IT responsibilities may need to be approached differently in a CJIS-governed environment.
People & Access
Technicians supporting systems containing or providing access to CJI may themselves fall within personnel-screening and access requirements.
Access should therefore be based on legitimate responsibilities rather than giving every technician unrestricted access to every system.
Accounts & Authentication
User accounts, administrative privileges, MFA, credential handling, and employee offboarding all affect the security of the environment.
An ordinary employee account and an administrative account should not automatically have the same level of access.
Remote & On-Site Support
The fact that a technician can technically connect to a system does not mean every remote-support method or workflow is appropriate.
The system involved, technician authorization, authentication, customer requirements, and type of information being accessed all matter.
Maintenance & Documentation
Patching, configuration changes, workstation maintenance, network changes, and troubleshooting need to be performed without weakening the safeguards surrounding the environment.
Useful documentation also improves continuity while sensitive infrastructure information remains protected.
Computer Ties Is Vetted for Michigan CJIS-Governed Work
Michigan State Police operates a Statewide IT Vendor Program for IT vendors used by multiple agencies. MSP states that the program facilitates fingerprinting and background checks for vendor personnel and centralizes those records so participating agencies do not need to duplicate the vetting process.
Computer Ties is enrolled in Michigan’s Statewide IT Vendor Program and maintains CJIS-related workforce requirements across the company.
Every Computer Ties employee is subject to:
Name-based background screening
Fingerprint-based background screening through the Michigan State Police CJIS process
Annual CJIS Online Security Awareness Training
A signed CJIS Security Addendum
Role-appropriate access to customer systems
Customer confidentiality requirements
Controlled handling of sensitive technical information
Security-focused support procedures for governed environments
The FBI Security Addendum exists specifically to establish security responsibilities where private contractors support criminal-justice systems or receive connectivity to CJIS systems.
This is why describing Computer Ties simply as “CJIS certified” would actually be less accurate than explaining what we do.
CJIS is a security policy and operating framework, not a general certification program for managed IT providers.
Computer Ties instead maintains the screening, training, agreements, and operational practices required for the CJIS-governed work we perform in Michigan.
Microsoft 365 GCC in a CJIS-Governed Environment
For eligible government and public-safety organizations, the Microsoft 365 environment should be considered alongside workstations, accounts, networks, authentication, and other security controls.
Microsoft 365 Government Community Cloud (GCC) is specifically available to eligible federal, state, local, and tribal government organizations and to certain nongovernment entities handling regulated government information.
Microsoft documents GCC commitments that include U.S.-based customer-content storage, logical separation from commercial Office 365 customer content, screened personnel access to customer content, and support for criminal-justice-information requirements.
Computer Ties can help with:
Evaluating commercial Microsoft 365 versus GCC
Confirming government-cloud eligibility requirements
Planning commercial-to-GCC migrations
Microsoft 365 government licensing guidance
User and mailbox administration
Multi-factor authentication
Administrative roles and permissions
Ongoing GCC tenant support
Microsoft 365 GCC can provide an important technology foundation for an organization subject to government requirements.
It does not, however, replace the organization’s responsibilities around employee access, endpoints, networks, training, policies, remote support, documentation, physical safeguards, or other required controls.
Where substantially more restrictive requirements apply — particularly certain CUI, ITAR, or defense-related workloads — GCC High may need to be evaluated separately.
Frequently Asked Questions
There is no general FBI-issued CJIS certification for managed IT providers comparable to certifications such as SOC 2 or a professional license.
CJIS is centered on the FBI CJIS Security Policy and the requirements governing agencies, systems, personnel, contractors, access, and protection of Criminal Justice Information.
Vendors working within those environments must meet the requirements applicable to their role rather than simply obtaining a universal “CJIS-certified vendor” badge.
Computer Ties is enrolled in Michigan’s Statewide IT Vendor Program and maintains the personnel screening, fingerprinting, training, Security Addendum, and support practices associated with its work in CJIS-governed environments.
Michigan State Police maintains this program for IT vendors serving multiple agencies and uses it to facilitate and centralize vendor personnel background-vetting records.
Every Computer Ties employee undergoes both name-based and fingerprint-based background screening.
Employees also complete annual CJIS Online Security Awareness Training and have signed CJIS Security Addendums.
These requirements apply across the Computer Ties workforce rather than to only one designated government technician.
No.
The IT provider is only one part of the environment.
The agency remains responsible for applicable policies, users, training, physical safeguards, technical controls, agreements, systems, access decisions, and other CJIS requirements.
Yes.
Computer Ties has experience supporting Michigan public-safety technology environments where LEIN and CJIS requirements affect system access, authentication, administration, maintenance, and support procedures.
Not necessarily.
The correct Microsoft environment depends on the organization, information being handled, systems, agreements, and applicable requirements.
Computer Ties can help determine whether GCC should be evaluated.
No.
Microsoft 365 GCC includes government-specific commitments relevant to criminal-justice workloads, but the Microsoft tenant is only one component of the organization’s overall environment.
Yes.
Computer Ties can help implement and administer MFA within supported systems while taking the requirements of the specific environment into account.
MFA strengthens authentication but does not replace the other required safeguards.
Remote support can be appropriate when the technician, authentication method, access controls, affected systems, and customer requirements support it.
The remote-support process should be evaluated in context rather than assuming every commercial remote-support method is appropriate for every CJIS system.
Administrative privileges should reflect legitimate job responsibilities rather than convenience.
Separating everyday user activity from elevated administrative access can reduce unnecessary privilege and aligns with sound security practice.
Work With an IT Provider Prepared for CJIS-Governed Environments
Government and public-safety organizations need an IT provider that understands that CJIS is more than a marketing label.
Computer Ties combines Michigan vendor-program participation, employee screening, fingerprint-based background checks, annual CJIS security-awareness training, signed Security Addendums, Microsoft 365 GCC experience, and security-focused IT practices to support qualifying government environments.
If your organization needs help with Microsoft 365 GCC, authentication, workstations, secure government networks, remote access, documentation, lifecycle planning, or broader public-safety IT support, start with a conversation.