Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8523 (Initial Public Draft)

Multi-Factor Authentication for Criminal Justice Information Systems: Implementation Considerations for Protecting Criminal Justice Information

Date Published: March 13, 2025
Comments Due: April 14, 2025
Email Comments to: psfr-nccoe@nist.gov

Author(s)

William Fisher (NIST), Jason Ajmo (MITRE), Sudhi Umarji (MITRE), Spike Dog (MITRE), Mark Russell (Appian Logic), Karen Scarfone (Scarfone Cybersecurity)

Announcement

Criminal and non-criminal justice agencies in the U.S. require the use of multi-factor authentication (MFA) to protect access to criminal justice information (CJI). MFA is important for protecting against credential compromises and other cyber risks such as attacks by cybercriminals or other adversaries that threaten CJI.

CJI is commonly accessed using computer-aided dispatch (CAD) and record management system (RMS) software, which communicate with a state-level message switch application. MFA architectures will likely need to integrate with one or both technologies. As agencies around the country begin to implement MFA solutions, the approaches they use require careful consideration and planning. This document provides a general overview of MFA, outlines design principles and architecture considerations for implementing MFA to protect CJI, and offers specific examples of use cases that agencies face today. It also outlines how CAD/RMS and message switch technologies can support standards and best practices that provide agencies with maximum optionality to implement MFA in a way that promotes security, interoperability, usability, and cost savings.

NOTE: A call for patent claims is included in the front matter of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy  Inclusion of Patents in ITL Publications.

Abstract

Keywords

authentication; credentials; criminal justice information (CJI); identity; identity federation; law enforcement; multi-factor authentication (MFA); single sign-on (SSO)
Control Families

Identification and Authentication

Documentation

Publication:
https://doi.org/10.6028/NIST.IR.8523.ipd
Download URL

Supplemental Material:
None available

Document History:
03/13/25: IR 8523 (Draft)

Topics

Security and Privacy

authentication

Laws and Regulations

First Responder Network Authority

Sectors

public safety