Guide
Sovereign data, and the CJIS rules that apply
Tribal justice data answers to two rulebooks at once: the FBI's CJIS Security Policy, a federal security floor, and the tribe's own authority over its data, framed as Indigenous data sovereignty. This guide explains both and where they meet.
The moment a tribe stores court records in a commercial cloud, both rulebooks apply: the federal security floor, and the tribe's inherent authority over its own data.
- Version 6.0 current CJIS Security Policy (Dec 2024)
- 256-bit AES at-rest encryption CJIS accepts
- 4 principles of CARE Indigenous data governance
- Sept 30, 2027 CJIS full-compliance deadline
Rulebook one: CJIS security
Any agency that touches criminal justice information is bound by the FBI CJIS Security Policy. Its current edition, Version 6.0, released in December 2024, is the largest update in over a decade and maps the whole policy to the NIST SP 800-53 control catalog at the Moderate baseline. It requires encryption of criminal justice information validated to the federal FIPS standard: at least 128-bit for data in transit, and AES up to 256-bit for data at rest outside a secure location, plus audit and access-control provisions.
The policy phases in with priority tiers, with full compliance for the lower-priority controls required by September 30, 2027. Whether CJIS binds a given tribe depends on how the tribal agency reaches national crime databases, so confirm the access channel.
Rulebook two: data sovereignty
Separately, Indigenous data sovereignty is the right of a Native nation to govern the collection, ownership, and use of its own data. It is operationalized through the CARE Principles for Indigenous Data Governance.
| CARE principle | What it means |
|---|---|
| Collective Benefit | Data use should benefit the nation and its members |
| Authority to Control | The nation governs who reaches its data and how |
| Responsibility | Those who hold the data are accountable for it |
| Ethics | The rights and wellbeing of the people come first |
The tension is concrete: mainstream data law holds that data is subject to the laws of the place it is stored. That is exactly what data sovereignty rejects, and exactly what happens when tribal records sit in a commercial cloud under another jurisdiction.
Where the two rulebooks meet
A good architecture satisfies both at once rather than trading one for the other. Encryption the tribe controls, hosting the tribe governs, and clear authority-to-control terms let a government meet the federal security floor without surrendering governance of its own records.
The CARE principles are a governance framework, not law. Their force in a purchase comes from the tribe writing them into its own data code and its vendor contracts.
Questions to ask any vendor
- Is criminal justice information encrypted at rest and in transit to the federal FIPS standard?
- Where does the database physically sit, and what law governs those servers?
- Who holds the encryption keys: the tribe, or the vendor?
- Does the contract state the tribe's authority to control its own data in plain terms?
Sources
- FBI CJIS Security Policy Resource Center · FBI CJIS Division. le.fbi.gov
- CARE Principles for Indigenous Data Governance · Global Indigenous Data Alliance. gida-global.org
- U.S. Indigenous Data Sovereignty Network · USIDSN. usindigenousdatanetwork.org
- NIST SP 800-53 Rev. 5, security and privacy controls · NIST. csrc.nist.gov