Bridge4PS is a secure collaboration platform designed for public safety information sharing and

operational coordination. Unlike criminal justice information systems and databases, Bridge4PS does

not directly query Criminal Justice Information (CJI) repositories or serve as a system of record for

criminal justice data.


Bridge4PS has consulted directly with the FBI CJIS Office regarding the applicability of the CJIS

Security Policy to our platform. Based on guidance received during those discussions, because

Bridge4PS does not directly query CJI repositories or function as a criminal justice database, it may

not be subject to the CJIS Security Policy in the same manner as systems that directly access, query, or

maintain CJI databases. However, the applicability and interpretation of CJIS requirements ultimately

rests with each state’s CJIS Systems Agency (CSA), CJIS Security Officer (CSO), and applicable agency

policies.


Bridge4PS was architected and implemented to the FedRAMP Moderate security baseline as part of a

U.S. Department of Homeland Security-funded effort. As a result, Bridge4PS meets the FedRAMP

Moderate security requirements and incorporates comprehensive security, auditing, access control,

encryption, monitoring, retention, and governance controls. Where CJIS requirements exceed the

FedRAMP Moderate baseline, Bridge4PS has implemented the higher standard where technically and

operationally feasible. Based on our review of the CJIS Security Policy and discussions with the FBI

CJIS Office, the requirements that do not directly align between Bridge4PS and the policy are

automatic session timeout, CJIS Security Addenda, and interagency information-sharing agreement

requirements.


Bridge4PS does not implement automatic session timeout because doing so would prevent users

from receiving real-time notifications and significantly impair the operational effectiveness of a

real-time collaboration platform. The applicability of CJIS Security Addenda is determined by the

applicable CJIS authority and may vary by state and use case. Some jurisdictions may also require

information-sharing agreements governing the exchange of Criminal Justice Information between

participating agencies. Such agreements are generally established between the agencies themselves

and are independent of Bridge4PS, although administering these requirements across large-scale,

multi-agency interoperability environments may present practical challenges.


Agencies evaluating vendor claims of CJIS compliance should understand how those claims address

these and other applicable requirements. Agencies remain responsible for determining the

appropriate use of Bridge4PS for the transmission, storage, retention, and management of Criminal

Justice Information in accordance with their state’s policies and procedures.


Organizations seeking clarification regarding the applicability of the CJIS Security Policy are

encouraged to consult their state’s CJIS Systems Agency or contact the FBI CJIS Information Security

Officer Program Office at iso@fbi.gov.


Please contact us through our help center at https://help.bridge4ps.com or email

support@bridge4ps.app if you have any questions.