FBI CJIS Security Policy v6.1 update
Public Sector Action
Summary
Hide ▲
Show ▼
FBI published CJIS Security Policy v6.1 on June 25, 2026, tightening requirements for organizations that handle CJI. The update raises SC-13 encryption strength for CJI in transit from 128-bit to 256-bit and sets SC-28 at 256-bit for CJI at rest. It also changes vulnerability scanning from quarterly to at least monthly, increasing the cadence of control verification. The policy now sets the current compliance baseline for agencies preparing audits and assessments.
Related Happenings
NIST NVD modernization RFI
Public Sector Action
H score21
First: 12.08.2026 15:30
Last: 12.08.2026 15:30
Sources 1
About this happening:
NIST published a request for information to modernize the National Vulnerability Database (NVD), seeking better handling of vulnerability data in an AI-shaped cybers...
NIST NVD modernization RFI
Public Sector ActionAbout this happening: NIST published a request for information to modernize the National Vulnerability Database (NVD), seeking better handling of vulnerability data in an AI-shaped cybers...
NIST/NVD risk-based CVE enrichment change
Public Sector Action
H score35
First: 16.04.2026 15:43
Last: 16.04.2026 15:43
Sources 1
About this happening:
NIST said the US National Vulnerability Database (NVD) will switch to a risk-based CVE enrichment model to cope with backlog growth. The change will drop enrichment...
NIST/NVD risk-based CVE enrichment change
Public Sector ActionAbout this happening: NIST said the US National Vulnerability Database (NVD) will switch to a risk-based CVE enrichment model to cope with backlog growth. The change will drop enrichment...
Anthropic launches Project Glasswing with Claude Mythos for vulnerability discovery
Security Tool/Service
H score58
First: 08.04.2026 12:16
Last: 08.04.2026 12:16
Sources 1
About this happening:
Anthropic’s Project Glasswing is now showing measurable results: since launching last month, the Claude Mythos Preview-based initiative has uncovered more than 10,000...
Anthropic launches Project Glasswing with Claude Mythos for vulnerability discovery
Security Tool/ServiceAbout this happening: Anthropic’s Project Glasswing is now showing measurable results: since launching last month, the Claude Mythos Preview-based initiative has uncovered more than 10,000...
Latest development: 03.06.2026 14:00
President Donald Trump signed a June 2 executive order that sets up a voluntary framework for developers of covered frontier models to give the US government access for cybersecurity review for up to 30 days before release, while expressly rejecting any mandatory licensing or preclearance requirement. The order directs NSA, CISA, and NIST to build a classified benchmark for determining which models cross the covered threshold and creates an AI cybersecurity clearinghouse led by the Treasury Department. The framework closely echoes Anthropic's Project Glasswing, which gives vetted partners early access to Claude Mythos Preview to scan critical software for vulnerabilities.
CISA orders federal agencies to remediate end-of-support edge devices
Public Sector Action
H score26
First: 05.02.2026 14:00
Last: 05.02.2026 14:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-02 to require FCEB agencies to inventory, update, and remove end-of-support edge devices within a specified timeframe....
CISA orders federal agencies to remediate end-of-support edge devices
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-02 to require FCEB agencies to inventory, update, and remove end-of-support edge devices within a specified timeframe....
FBI Operation Winter SHIELD cyber resilience campaign
Public Sector Action
H score28
First: 29.01.2026 18:50
Last: 29.01.2026 18:50
Sources 1
About this happening:
The FBI launched Operation Winter SHIELD, issuing ten recommended actions to help organizations harden IT and OT environments against cyber-attacks and malicious...
FBI Operation Winter SHIELD cyber resilience campaign
Public Sector ActionAbout this happening: The FBI launched Operation Winter SHIELD, issuing ten recommended actions to help organizations harden IT and OT environments against cyber-attacks and malicious...
Timeline
-
21.09.2026 17:02 1 articles · 2h ago
FBI releases CJIS Security Policy v6.0
Technical Analysis UpdateFBI released CJIS Security Policy v6.0 on December 27, 2024, completing the policy modernization effort and moving CJIS toward a control-based structure closely aligned with NIST SP 800-53.
Show sources
- FBI's CJIS v6.1: What Security Teams Need to Know. — www.bleepingcomputer.com — 21.09.2026 17:02
-
21.09.2026 17:02 2 articles · 2h ago
FBI publishes CJIS Security Policy v6.1
Legal Policy Action UpdateFBI published CJIS Security Policy v6.1 on June 25, 2026, addressing omissions, corrections and additions highlighted throughout 2025 and setting the current policy baseline for agencies handling CJI. The update raises SC-13 encryption for CJI in transit from 128-bit to 256-bit, sets SC-28 for CJI at rest to at least 256-bit, and changes vulnerability scanning from quarterly to at least monthly.
Show sources
- FBI's CJIS v6.1: What Security Teams Need to Know. — www.bleepingcomputer.com — 21.09.2026 17:02
- FBI's CJIS v6.1: What Security Teams Need to Know. — www.bleepingcomputer.com — 21.09.2026 17:02