NCIC Terminal Agency Coordinator (TAC) Roles and Audit Responsibilities 3 — Questions and Answers
Question 1: The TAC is responsible for ensuring that what specific type of security screening is completed for all personnel with NCIC access?
- A credit history check only
- A CJIS-compliant background investigation including fingerprint-based criminal history check (Correct answer)
- A social media review conducted by the TAC personally
- A character reference check from two supervisors
Correct answer: A CJIS-compliant background investigation including fingerprint-based criminal history check
CJIS Security Policy requires a fingerprint-based criminal history background check for all personnel with access to Criminal Justice Information, including NCIC — the TAC ensures this is completed.
The CJIS Security Policy requires that all personnel who have access to Criminal Justice Information (CJI) — including NCIC — undergo a CJIS-compliant background investigation. This investigation includes a fingerprint-based criminal history check through the FBI's Next Generation Identification (NGI) system to identify any disqualifying criminal history. The TAC is responsible for ensuring this screening is completed before access is granted and that documentation of the completed screening is maintained. Personnel who have disqualifying criminal history (including felony convictions and certain misdemeanors) may be prohibited from accessing NCIC. The TAC must remain current on CJIS Security Policy updates regarding screening requirements.
Question 2: What is the TAC's responsibility when the agency receives a policy update or change from the CJIS Systems Agency?
- Forward the update to the IT department for implementation
- Review the policy change, determine its operational impact, update agency procedures accordingly, train affected personnel, and ensure implementation (Correct answer)
- Acknowledge receipt but defer implementation until the next triennial audit
- Consult with other TACs in the region before implementing
Correct answer: Review the policy change, determine its operational impact, update agency procedures accordingly, train affected personnel, and ensure implementation
When policy updates are received, the TAC must review them, assess their operational impact, update agency procedures, train affected personnel, and ensure timely implementation.
One of the TAC's ongoing responsibilities is staying current on NCIC and CJIS policy changes and ensuring timely implementation within the agency. When a policy update is received from the CSA or the FBI CJIS Division, the TAC must: carefully review the changes to understand their scope and implications; assess the operational impact on agency procedures, forms, and practices; update agency standard operating procedures to reflect the new requirements; communicate the changes to all affected personnel through appropriate training or briefings; and document the implementation process. Policy changes must be implemented within the timeframe specified in the update, which may be immediate for security-related changes. Failure to implement policy updates is a compliance violation.
Question 3: What records must a TAC maintain to demonstrate compliance with NCIC user access controls?
- Only the total number of NCIC-authorized users
- Individual user access logs, training completion records, signed user agreements, and documentation of access terminations when personnel leave or change roles (Correct answer)
- A summary report submitted to the FBI annually
- Budget records showing the cost of NCIC training per employee
Correct answer: Individual user access logs, training completion records, signed user agreements, and documentation of access terminations when personnel leave or change roles
TACs must maintain individual user records including access logs, training documentation, user agreements, and records of access modifications or terminations to demonstrate compliance with access control requirements.
NCIC and CJIS compliance requires TACs to maintain comprehensive records for each authorized user throughout the user's period of access and beyond. These records include: training completion certificates or logs for each required course; signed user acknowledgment agreements specifying the individual's agreement to NCIC terms; background screening documentation; access activation records; and, critically, documentation of access termination when personnel leave the agency, change roles, or are no longer authorized. Access termination documentation is particularly scrutinized in audits because allowing terminated employees or employees in new non-NCIC roles to retain access is a serious compliance finding. Records must be organized and readily accessible for audit review.
Question 4: What is the TAC's role when a law enforcement officer reports that they may have released NCIC information to an unauthorized person?
- Privately advise the officer to be more careful in the future
- Treat the disclosure as a security incident, conduct an initial assessment, document findings, and report to the CSA as required by the CJIS Security Policy incident response requirements (Correct answer)
- Consult with the agency attorney before taking any action
- The TAC has no role — this is handled exclusively by the officer's supervisor
Correct answer: Treat the disclosure as a security incident, conduct an initial assessment, document findings, and report to the CSA as required by the CJIS Security Policy incident response requirements
Potential unauthorized disclosure of NCIC information must be treated as a security incident, documented, assessed, and reported to the CSA in accordance with CJIS Security Policy incident response requirements.
When a potential unauthorized disclosure of NCIC information is reported, the TAC must treat it as a formal security incident requiring structured response under the CJIS Security Policy. The TAC should: document the report in detail including who was present, what information was disclosed, to whom, and under what circumstances; conduct an initial assessment to determine the scope and nature of the potential violation; notify agency leadership; and report the incident to the CJIS Systems Agency as required by the Security Policy incident reporting requirements. The CSA will determine whether escalation to the FBI is required. Even if the unauthorized disclosure was inadvertent, it must be formally documented and reported — concealing it to protect the officer would itself be a serious violation.
Question 5: How does a TAC verify that the agency's NCIC transactions are being used appropriately and not for personal inquiries?
- By asking officers to self-report any personal queries they may have run
- By regularly reviewing transaction logs and comparing them against documented law enforcement activities (incidents, CAD records, arrests) to identify transactions without a documented law enforcement purpose (Correct answer)
- By conducting random polygraph examinations of officers
- By requiring officers to submit written justifications for every NCIC query before running it
Correct answer: By regularly reviewing transaction logs and comparing them against documented law enforcement activities (incidents, CAD records, arrests) to identify transactions without a documented law enforcement purpose
The TAC audits transaction logs by comparing NCIC queries against documented law enforcement activities to identify transactions that lack a documented official purpose — a key indicator of potential misuse.
To detect personal or unauthorized NCIC queries, TACs must regularly pull and review the agency's NCIC transaction logs. The core audit technique is matching logged queries against documented law enforcement activities: CAD (computer-aided dispatch) records, incident reports, arrest records, and case files. Every legitimate NCIC query should be traceable to a specific law enforcement event or documented purpose. Queries that cannot be matched to any documented official activity are potential indicators of personal use, browsing, or other misuse. TACs look for patterns such as queries run on weekends when the officer was not on duty, queries on individuals with no case nexus, or high volumes of queries by a single user without a proportionate volume of documented case work.
Question 6: When an agency is found to be non-compliant in a CJIS triennial audit, what is the TAC's primary responsibility in the corrective action process?
- The TAC must resign from their position as TAC
- The TAC leads the development and implementation of a corrective action plan addressing all audit findings, tracking progress, and reporting to the CSA until all findings are resolved (Correct answer)
- The TAC submits a written apology to the FBI CJIS Division
- The TAC is personally fined for each compliance finding
Correct answer: The TAC leads the development and implementation of a corrective action plan addressing all audit findings, tracking progress, and reporting to the CSA until all findings are resolved
Following a non-compliant audit finding, the TAC leads the corrective action planning and implementation process, tracking progress until all findings are resolved to the CSA's satisfaction.
When a CJIS triennial audit results in non-compliance findings, the TAC assumes a central role in the corrective action process. The TAC must: work with agency leadership to develop a written corrective action plan that specifically addresses each audit finding with concrete remediation steps and target completion dates; assign responsibility for each corrective action to appropriate personnel; track progress against the plan; document completed corrective actions with evidence; and report progress to the CSA at the intervals specified in the corrective action agreement. The CSA monitors compliance until all findings are satisfactorily resolved. The TAC's effectiveness in driving corrective action directly impacts the agency's ability to restore full NCIC compliance standing and avoid further sanctions.
The TAC is responsible for ensuring that what specific type of security screening is completed for all personnel with NCIC access?