1 of 80

Terminal Agency �Coordinator (TAC)�Training

Wyoming Attorney General’s Office

Division of Criminal Investigation

Criminal Justice Information Services (CJIS)

Control Terminal Unit

2 of 80

Introduction

Why is a TAC necessary for my agency?

  • CJIS Security Policy Section 3.2.2(2)(d):
    • The CSO, or designee, shall ensure that a Terminal Agency Coordinator (TAC) is designated within each agency that has devices accessing CJIS systems.

  • CJIS Security Policy Section 3.2.3:
    • The TAC serves as the point-of-contact at the local agency for matters relating to CJIS information access. The TAC administers CJIS systems programs within the local agency and oversees the agency’s compliance with CJIS systems policies.

3 of 80

Introduction

Purpose and Objective

    • Inform Terminal Agency Coordinators (TACs) of their responsibilities

    • Ensuring compliance with state and NCIC policy and regulations

4 of 80

Introduction

Training consists of:

      • Introduction
      • System Security
      • System User Access
      • User Agreements
      • Validation Requirements
      • Audits
      • Quality Control
      • Agency Policy and Procedures
      • Terminal Equipment Management
      • Messenger Log Search
      • TAC Meetings
      • TAC Regions

5 of 80

TAC Responsibilities

    • Ensuring compliance with NCIC and State policy and regulations, including validation requirements

    • The TAC will be the primary contact between the CJIS System Agency (CSA), Control Terminal (CT) Unit and their respective department, as well as their sub-user agencies

6 of 80

TAC Responsibilities (Cont’d):

    • Provide for initial NCIC, NLETS, CJIS Security and WCJIN training of terminal agency operators. Provide for basic prescribed training for:
      • Criminal Justice Administrators
      • Criminal Justice Practitioners (Officers, county/city attorneys, municipal/county judges, etc.)
      • Records Personnel (not only within their respective agency, but also to all sub-user agencies)
      • IT Personnel
    • Implement agency training program

7 of 80

TAC Responsibilities (Cont’d):

    • Responsible for validation of all records entered through their respective terminal devices
    • Represent agency at TAC meetings
    • Coordinate the signing of User Agreements
    • Establish written procedures for their agency
    • Notify the CT Unit of all new terminal operators
    • Responsible for managing system security and ensuring agency has someone designated as the Local Agency Security Officer (LASO)
    • Assist in triennial agency audits

8 of 80

TAC Responsibilities (Cont’d):

    • Assist with online terminal user testing annually
    • Provide Training and testing for MDT users (annually)
    • Ensure all IT personnel take the online Security Awareness Certificate testing annually
    • Ensure all sub-users sign a “Rules of Behavior”
    • Ensure all agency personnel who have access to CJI sign a “Rules of Behavior” and have them accomplish role-based security and privacy training prior to granting access
        • All individuals with unescorted access to physically secure location
        • General users
        • Privileged Users
        • Organizational Personnel with Security Responsibilities

9 of 80

TAC Responsibilities (Cont’d):

TAC Resources

  • Open an Internet Browser

      • Then click on Terminal Agency Coordinators and dispatchers

10 of 80

System Security

Terminal and Data

    • Data accessible via NCIC,Nlets and WCJIN is provided for criminal justice purposes only
    • Authorized system users are those agencies which have an NCIC assigned ORI
    • Assignment of an ORI is acknowledgement that the agency meets the criteria of “criminal justice agency” defined by NCIC policy

11 of 80

System Security cont.

System Security Measures

    • Is the responsibility of both CJIS System Agency (CSA/Control Terminal) as the system provider, and the system user agencies

    • This not only includes physical, technical and personnel security requirements, but also extends to the safeguarding of information derived from the systems.

12 of 80

System Security cont.

The CT provides access security in the form of computer edits:

    • These edits verify
      • The device is authorized to conduct transactions
      • That the ORI belongs to the terminal sending the message (or has authorization to use that ORI)
      • That the user logon ID is valid
      • That the operator logged on is authorized to conduct the attempted transaction
    • Failure to pass these edits result in denial of system access or rejection of the transaction being performed

13 of 80

System Security cont.

User Agency’s Security Responsibility

    • Maintaining their terminal(s) in a secure environment with limited access
      • Such sites include locations or vehicles housing Mobile Date Terminals (MDT’s) or laptop computers capable of accessing FBI CJIS records information
      • All visitors to computer centers and/or terminal areas must be accompanied by authorized personnel at all times
      • All unescorted personnel MUST have security awareness training (CJIS Online)

14 of 80

System Security cont.

User Agency’s Security Responsibility cont.

    • Screening personnel who have authorized terminal access
      • This includes fingerprints being sent to DCI, inquiries of NCIC III and appropriate state files to verify the suitability of the individual for access. This must be completed within 30 days of assignment
      • All requests for access shall be made as specified by the CSO.
  • If a felony conviction of any kind exists, the hiring authority in the Interface Agency shall deny access to CJI. However, the hiring authority may ask for a review by the CSO in extenuating circumstances where the severity of the offense and the time that has passed would support a possible variance

15 of 80

System Security cont.

User Agency’s Security Responsibility cont.

  • If the person already has access to CJI and is subsequently arrested and or convicted, continued access to CJI shall be determined by the CSO. This does not implicitly grant hiring/firing authority with the CSA, only the authority to grant access to CJI.
  • If the CSO or his/her designee determines that access to CJI by the person would not be in the public interest, access shall be denied and the person's appointing authority shall be notified in writing of the access denial.
  • Support personnel, contractors, and custodial workers with access to physically secure locations or controlled areas shall be subject to a state and national fingerprint-based record check unless these individuals are escorted by authorized personnel at all times

16 of 80

System Security cont.

Safeguarding information obtained via the systems

      • Any agency participating in NCIC, and having direct access, must assume responsibility for and enforce NCIC System security with regard to all other agencies which it, in turn, services (i.e. has user agreements with)
      • The terminal equipment area must have adequate physical security to protect against any unauthorized personnel gaining access to, or viewing of, the terminal equipment or to any of the stored data

17 of 80

System Security cont.

Safeguarding information obtained via the system (Cont’d)

      • Terminal agencies having access to NCIC must provide trained and qualified operators at all times.
      • Terminal equipment operators should use the terminal devices only for those purposes for which they are authorized

18 of 80

System Security cont.

    • The data stored in NCIC, Nlets and the WCJIN telecommunications system is criminal justice information and must be protected to ensure correct, legal, and efficient dissemination and use
    • The individual receiving a request for criminal justice information must ensure that the person requesting the information is authorized to receive the data
    • Each criminal justice agency authorized to receive NCIC information must have appropriate written standards for discipline for system policy violators

19 of 80

System Security cont.

III/CHRI RECORD DATA SECURITY

    • III/CHRI records must be maintained in a secure records environment
    • Agencies should screen all employees (records clerks, custodial staff, support staff, contractors, etc) having access to record storage areas containing FBI CJIS III data
    • When retention of III/CHRI records is no longer required, final disposition will be accomplished in a secure manner so as to preclude unauthorized access or use (When no longer needed - Shred)

20 of 80

System Security cont.

NCIC/CSA Sanctions

    • Purge of an agency's NCIC records and discontinuance of system access are the two ultimate sanctions
    • Issues will be dealt with from the lowest level possible
      • Verbal notice from CSA to terminal agency
      • Letter of request for compliance - CSA to terminal agency

21 of 80

System Security cont.

NCIC/CSA Sanctions (Cont’d)

      • Letter of intent to remove from system if deficiency is not corrected - CSA to terminal agency
      • NCIC advisory letter to the governor - CSA to terminal agency – removal of records and discontinuance of service is imminent
      • Removal from system includes purge of all records and discontinuance of service pending reinstatement

22 of 80

System Security cont.

The TAC and local agency POC’s responsibilities shall also include:

    • Developing information security training programs (CJIS Online and nexTEST)
    • Conducting/assisting presentation of such programs (CJIS Online and nexTEST)
    • Devising a form of feedback to measure the validity of both the material being furnished and the actual training programs
    • Each local agency security officer (LASO) is also responsible for maintaining a current network topology of the local system

23 of 80

System Security cont.

Disposal of Media

    • All data associated with the FBI CJIS systems records shall be securely stored and/or disposed of to prevent access by unauthorized personnel. Local agencies should establish policy and procedures for:
      • Disposal of all fixed storage media, e.g., hard disks, RAM disks, removable media back-up devices, etc
      • Disposal procedures should include a method sufficient to preclude recognition or reconstruction of information
      • A method of verification the procedures were successfully completed

24 of 80

System User Access

ORIGINATING AGENCY IDENTIFIER (ORI)

    • An NCIC ORI is a nine character identifier assigned by the FBI NCIC to an agency which has met the established qualifying criteria for ORI assignment to identify the agency transactions in the NCIC System
    • The CSO will submit necessary documentation, supplied by the user agency, when requesting the assignment of an ORI
    • Further information may be obtained in the TAC Manual

25 of 80

System User Access cont.

TERMINAL OPERATOR SIGNON NUMBER

    • The TAC notifies the CT via the Terminal Operator Logon Request Form of new terminal operators and their access (Full, Limited or MDT)
    • The form designates the information required and includes a space for a challenge question and answer, which must be completed at the time of the request
    • The form can be emailed to dci-controlterminal-all@wyo.gov or faxed to the CT at 307-777-7301

26 of 80

System User Access cont.

TERMINAL OPERATOR SIGNON NUMBER

    • Each user is assigned a unique user ID number
    • The TAC shall notify the CT anytime a users status changes by sending a User Log on Request Form, this includes removing the user from the system
    • This is very important to keep records complete and up to date

27 of 80

System User Access cont.

TRAINING, TESTING, AND RETESTING

    • The TAC will provide for initial NCIC, Nlets and WCJIN training of all new employees (training material has been posted on the TAC site)
    • The CSA no longer provides the 3 day training before or after Dispatch Basic at the WLEA
    • Within six months of initial employment or assignment a terminal operator must be functionally tested
      • NCIC Certificate (Full, Limited or MDT Access)

28 of 80

System User Access cont.

TRAINING, TESTING, AND RETESTING

    • The CSA no longer conducts training at WLEA
      • All personnel will complete training/certification using the CJIS Online Program. It has different levels of certification depending on the persons level
        • Unescorted access to physically secure location (custodial personnel)
        • General User – Personnel with access to CJI (clerks, admin)
        • Priviledged User – Personnel with physical and direct/logical access (dispatchers, officers). These personnel will obtain security training/certification using the nexTEST Program
        • Organizational Personnel with Security Responsibilities – IT personnel

29 of 80

System User Access cont.

TRAINING, TESTING, AND RETESTING

    • All terminal operators whether Full, Limited, MDT, or OW must test annually

30 of 80

User Agreements

An agency requesting access to FBI CJIS Division’s databases must enter into a written agreement with the CSA

    • Agency must adhere to FBI CJIS Division policies which include:
      • Audit
      • Dissemination
      • Hit Confirmation
      • Logging
      • Quality Assurance
      • Screening (pre-employment)
      • Security
      • Timeliness
      • Training
      • Use of the System
      • Validation

31 of 80

User Agreements cont.

TERMINAL AGENCY

    • The TAC must keep NCIC User Agreements current with the CSA
    • New User Agreements need to be signed when there is a change in the terminal agency administrator
    • The TAC shall contact the CSA for new User Agreements to be drawn up and sent for appropriate signatures

32 of 80

User Agreements cont.

SUB-USER AGENCIES

    • A sub-user agency is one in which they do not have a terminal and get their information from a primary terminal agency
    • The TAC shall keep User Agreements current for all sub-user agencies that their agency serves
    • New Sub-User Agreements need to be signed when there is a change in administrative personnel of either agency

33 of 80

Validations

VALIDATION REQUIREMENTS - NCIC

  • Validations will be accomplished via an online NCIC validation application through the message switch.
  • NCIC records in need of validation will automatically be sent to the ORI of the record. If a record is entered with WY0110408, the device associated with WY0110408 will receive the validation notification. Agencies with multiple terminals will need to check each terminal for validation notifications.

34 of 80

Validations cont.

  • This affects NCIC Validations only. Agencies will still be required to follow validation guidelines to ensure the record being validated is valid, accurate, and up to date.

35 of 80

Validations cont.

  • The information housed in criminal databases is only useful for protecting the public and officer safety if it is valid. Consequently, NCIC requires annual validation by all law enforcement agencies of information housed in the NCIC database. In a manual system, the process can be laborious, error-prone and lengthy—resulting in non-compliance with NCIC.

  • The OpenFox™ Online Validation Application streamlines the process through automation, accurate reporting, and a user friendly interface which reduces keystrokes and increases efficiency.

36 of 80

Validations cont.

  • Validation transactions run through OpenFox™ Desktop provides a secure, encrypted, and reliable communications pathway to the OpenFox™ Message Switching System. All validation transactions take full advantage of this feature and pass through the Desktop FoxTalk™ communications session.

  • The application generates and sends notification messages to the owners of records. The notification messages are sent immediately, as well as at the 10 and 20 day marks to report progress and provide reminders to inform the agency that there are records requiring validation for the current cycle.

37 of 80

Validations cont.

An example of the ORI Notification message is shown below:

 

THIS MESSAGE SUMMARIZES THE JUNE RECORDS REQUIRING VALIDATION BY ORI/WY0XX0000 WITHIN 30 DAYS OF THIS NOTICE.

 

WANTED PERSON: 10

STOLEN VEHICLE: 20

PROTECTION ORDER: 5

 

TOTAL RECORDS: 35

38 of 80

Validations cont.

The message will be sent to the ORI on the record, i.e., if WY0XX0006 is on the record, the message will be sent to that ORI not, WY0XX0000. Someone will need to log into all terminals at their respective agency.

  • If your agency has multiple terminals, it is HIGHLY RECOMMENDED that you modify all NCIC records to the ORI that is on the terminal that will be logged in and manned 24 / 7 / 365.

  • Otherwise, all of your terminals must be logged in and manned 24 / 7 / 365 or you will miss some of the records that require validation.

  • Records that are not validated by the established due date, are subject to removal from the NCIC database by the Control Terminal or by NCIC.

39 of 80

Validations cont.

If the record contains the ORI of a sub-user, then that message will be sent to whatever terminal is authorized to use the sub-user’s ORI.

  • The OpenFox™ Validations process is a transaction based system that can tightly integrate with OpenFox™ Messenger. With OpenFox™ Messenger the user can retrieve reports directly to the workstation and through the use of hyper-link transactions can conveniently and efficiently validate records.

  • OpenFox™ Messenger workstation utilizes the QVAL, QVAD, QVAG, BVAL, and VAL transactions.

40 of 80

Validations cont.

An example of the Validations forms are shown within the OpenFox™ Forms Menu :

41 of 80

Validations cont.

  • Query Validation Global (QVAG) and Batch Validation (BVAL) are for Control Terminal Use Only!

  • Query Validation Global (QVAG) allows the Control Terminal to retrieve a statewide summary of records that require validation. Additionally it provides the Control Terminal with a report on each agency, showing the amount and what kind of record needs validation. These amounts will decrease as the records are validated. So when all the records for a particular ORI have been validated, the report will show zero.

42 of 80

Validations cont.

43 of 80

Validations cont.

Despite the system automating the validation process through use of the ORI notification message each of the below OpenFox™ Messenger transactions can be run independently.

The QVAL transaction is executed to retrieve the summary of records that require validation by ORI. The general format of the message will follow the NCIC format guidelines.

  • An example of the OpenFox™ Messenger QVAL Form is shown below:

44 of 80

Validations cont.

  • The Month (MON) field specifies which month’s validation records to process. The field must be a numeric value of 01 (January) – 12 (December).

  • After successfully running the QVAL transaction the user is presented with a summary of records that require validation for the MON and ORI provided within the QVAL query.

  • Each row contains a hyper link which, when clicked, will initiate a new QVAD transaction to the OpenFox™ Message Switch. This transaction retrieves the details of the records requiring validation.

45 of 80

Validations cont.

Below is a screen shot of a QVAL response within OpenFox™ Messenger:

46 of 80

Validations cont.

The workstation provides the opportunity to request the detail records requiring validation. The QVAD transaction is used to specify the type and number of records to be returned for validation processing at the workstation.

An example of the OpenFox™ Messenger QVAD Form:

47 of 80

Validations cont.

After successfully running the QVAD transaction the user is presented with record detail of the record(s) to be validated.

48 of 80

Validations cont.

The Record Type (FIL) field is defined via the following NCIC standard values:

B = Boat �C = Convicted person on supervised release �G = Gun �H = Protection Order 

J = Identity Theft�M = Missing person �L = License plate �P = Parts

S = Security

T = Gang/Terrorist Member 

U = Unidentified person �V = Vehicle

W = Wanted person �X = Sexual Offender 

Z = Gang/Terrorist Reference Group

49 of 80

Validations cont.

  • In order to validate a record, the agency must modify the contents of the VLN field within a given record. The VAL transaction is used is when an agency has determined an individual record is ready to be validated.
  • The hyperlinks at the bottom of the page can be used rather than opening separate forms. For example, “Validate this Record” would appear as:

50 of 80

Validations cont.

This form is pre-filled to submit the proper modify message key after a user clicks on the “Validate this Record” link within the QVAD response. In addition, Messenger will parse the NCIC number and the OCA number from the record details and it will use these values to pre-fill the corresponding fields on the form. Messenger also pre-fills the “Name of Validator” field with the name of the user currently signed on.

  • VLN Field Trigger Processing

  • The standard message is sent with one additional function to be triggered. The modification of the VLN field will be used as the flag to indicate to the validations application to update the VLD record and mark that this particular record has been validated. Subsequent requests for the list of records to be validated will not include the records that have been previously been validated. Also when a record is cancelled from NCIC as a result of the validation, the VLD record will be flagged to indicate that it has been validated.

51 of 80

Validations cont.

  • Occasionally records will be cancelled or cleared prior to the record being validated, but after that month’s validation list has been sent.

  • When this occurs it will be necessary to contact the control terminal to have the record removed from the validation list.

  • Each of the validation transactions specified above will be assigned the appropriate security role. OpenFox™ Desktop will dictate access to the validation forms and message keys based on these security roles.

  • This means that not just anyone at the agency can validate records. Their account must be set up with this particular permission in the Message Switch.

52 of 80

Validations cont.

    • The following are guidelines to be implemented during the validation process:
      • Check each NCIC entry on the validation listing with your files to insure it is complete, active, valid, and all supporting documentation is in the case file and immediately available for hit confirmation
      • Remove all records from NCIC that are no longer current
    • The following are guidelines to be implemented during the validation process:
      • Review each entry and insure the record contains all available information. Check the following:
        • All information in the record is accurate and up to date
        • That the information for blank fields is still unavailable
        • Check the entry format used to make the entry to insure that additional fields have not been added
        • Check that codes for current fields are still correct

53 of 80

Validations cont.

Ensure that all supporting documentation is in the case file; such as warrants, missing person reports, theft reports, vehicle registration for vehicle and license plate entries, protection orders, etc

54 of 80

Validations cont.

VALIDATION REQUIREMENTS – Wyoming Warrants

    • We no longer require validation of Wyoming Warrants
      • If a current listing of active warrants is desired, please contact the Control Terminal

55 of 80

Audits

GENERAL

    • Each CSA is required to establish a system to triennially audit every terminal agency which operates workstations, access devices, MDTs, or laptop computers to ensure compliance with agency and FBI CJIS Division’s policy and regulations
    • In addition to the audits conducted by all CSAs, each CSA and random agencies shall be audited at least once every three years by the FBI CJIS Audit Unit
    • The objective of this audit is to verify adherence to FBI CJIS policy and regulations and is termed a compliance audit
    • A compliance audit may be conducted on a more frequent basis should it be necessary due to failure of an agency to meet standards

56 of 80

Audits cont.

SECURITY AUDIT CAPABILITY

    • A security audit shall be performed by the CJIS Audit Unit, concurrent with the scheduled triennial agency audit, to measure the agency’s conformity to the CJIS Security Policy provisions

TECHNICAL SECURITY AUDITS

    • A technical security audit shall be performed triennially of every terminal agency by the CSA’s ISO, or his/her designee, to measure the agency’s conformity to the CJIS Security Policy in regards to technical security
    • Every terminal agency will be required to provide the CSA with a network and/or system overview schematic for the agency, including the location of firewalls and/or firewall type devices

57 of 80

Audits cont.

CJIS SYSTEMS AGENCY

    • The CSA has established systematic audits to guarantee the completeness, accuracy and timeliness of all record information in the system, as well as compliance with system and technical security, dissemination, training, policy and procedural standards and requirements
    • The CSA will advise an agency via email when their audit is due to be accomplished. This will be accomplished either by an online audit tool or by an in-person audit.
    • Audits will be scheduled by TAC Region

58 of 80

Audits cont.

CJIS SYSTEMS AGENCY

    • The objective of this audit is to verify adherence to rules, regulations and policy of the NCIC, Nlets and WCJIN systems
    • A complete audit report, including the audit of any agency they serve, will be sent to the terminal agency administrator as well as the TAC
      • The audit report will include those areas which need corrected
      • In some instances sanction letters may be sent to the TAC and the agency administrator
    • Audits may be conducted on a more frequent basis should it be necessary due to failure to meet the standards of compliance

59 of 80

Audits cont.

AUDIT SCHEDULE

    • Audits will be conducted on a triennial basis:
      • TAC Region 1 – 2027
      • TAC Region 2 – 2025
      • TAC Region 3 – 2026

60 of 80

Audits cont.

CHRI RECORDS

    • Audits of the CHRI (Criminal History Record Information) reports will be performed to ensure:
      • The requestor is authorized to receive the information
      • The operator is authorized to access the information
      • Proper dissemination was accomplished
      • To detect possible occurrences of misuse of the CHRI records

61 of 80

Quality Control

TERMINAL AGENCY

    • Each terminal agency that enters records into NCIC should develop quality control procedures
    • Once a record is entered into the NCIC system, the following steps must be accomplished:
      • After the record is accepted by NCIC, the terminal operator must Obtain a copy of the entry as it exists in NCIC
      • The entering operator must check the entry for accuracy and initial and date the entry hardcopy
      • The second person double checking the entry for accuracy must also initial and date the entry hardcopy

62 of 80

Quality Control

TERMINAL AGENCY

    • Any errors noted during this process should immediately be corrected. Corrected copies of the entry must then be initialed and dated when again checked for accuracy

63 of 80

Quality Control

CONTROL TERMINAL

    • All entries will be quality control checked by the CT for accuracy and completeness

    • The Control Terminal will contact agencies with corrections needed.

    • We do this to follow guidance in the NCIC manual

64 of 80

Quality Control

NCIC

    • NCIC personnel randomly check records for accuracy. Errors discovered are classified as serious errors or non-serious errors
      • For serious errors, NCIC will cancel the record and transmit a $.E. administrative message with a copy of the entry to the entering agency
      • For non-serious errors, NCIC will mail a letter to the CSA and in turn the CSA will forward a copy of the letter or a similar letter to the entering agency so corrective action can be taken

65 of 80

Quality Control

AGENCY WRITTEN PROCEDURES

    • Each agency shall have written procedures to follow when a Quality Control Error Notice is received from the CSA or NCIC
    • Procedures should show how corrections are to be made (e.g., contact primary case officer or correct the entry under their own authority)

66 of 80

Agency Policy and Procedures

STANDARDS

    • Written policy and procedures for terminal agencies shall contain at least the minimum standards required by NCIC, CJIS Security Policy, NLETS and WCJIN and shall not supersede/override any set forth by these systems

TOPICS/GUIDELINES

    • The following is a list of topics that should be used as a guideline in the development of an agency's written procedures

67 of 80

Agency Policy and Procedures (cont.)

TERMINAL/DATA SECURITY

    • Physical security of the terminal equipment devices
    • Restriction of terminal access to a limited, minimum number of authorized personnel. Local agency procedures should include who can have access and when, and who will require access for official purposes, training, etc

68 of 80

Agency Policy and Procedures cont.

TERMINAL/DATA SECURITY

    • Procedures for conducting background checks prior to hiring terminal operators, records personnel, IT personnel and other personnel who will have terminal access. Procedure should include:
      • Who will conduct the check
      • What will be checked and how
      • The use of III and state criminal history files utilizing

Purpose Code J

69 of 80

Agency Policy and Procedures cont.

TERMINAL/DATA SECURITY

    • Who is authorized to request terminal derived data through your terminal
    • Procedures to prevent unauthorized access/use of terminal derived information. This should include:
      • How do you give the information to the requestor
      • How and where do you secure the data until disseminated
      • Dissemination of criminal history/terminal derived data
      • How do you accomplish dissemination and secondary dissemination logs
      • What can terminal derived information be used for

70 of 80

Agency Policy and Procedures cont.

TERMINAL/DATA SECURITY

    • Password security should be addressed to include:
      • When and how to change passwords
      • Not allowing personnel to use someone else's operator ID and password
    • Procedures for which ORI is to be used in the ORI field and the Control Field and when, and a list of authorized sub-user ORI's and their personnel that are authorized to access via each ORI

71 of 80

Agency Policy and Procedures cont.

NCIC REQUIREMENTS

    • NCIC requires that jail facilities accomplish NCIC inquiries before a person is released from incarceration and for persons visiting an inmate/prisoner
    • Procedures regarding who conducts your agency's quality control of entries into NCIC and when this is accomplished. Who shall conduct the second-party check of these records and when it is done

72 of 80

Agency Policy and Procedures cont.

NCIC REQUIREMENTS (Cont’d)

    • Procedure shall include a list of what supporting documentation should be kept in the case file in support of an NCIC entry (Warrant, RQ, DQ, Coroner's report, documentation for adult missing, incident/case reports, etc)
    • Action to be taken when NCIC $ messages are received, to include $.H., $.N., $.M., $.L., $.E., and $.P. messages (See next slide)

73 of 80

Agency Policy and Procedures cont.

NCIC REQUIREMENTS (Cont’d)

    • NCIC $ messages:
      • $.H. – Hit/Delayed Inquiry Hit notification
      • $.N. – Wanted/Unidentified/Missing No Match Notification
      • $.M. – Unidentified/Missing Person Match Notification
      • $.L. – Locate Notification
      • $.E. – Serious Error Notification
      • $.P. – Purge Notification

74 of 80

Agency Policy and Procedures cont.

VALIDATIONS

    • Who accomplishes the validations
    • How agencies contact the victim/complainant for property and missing person records
    • Procedure for contact and verification with the county or district attorney for wanted person records
    • Who reviews the records for accuracy and completeness
    • What new documentation (criminal records, DQ, RQ, etc) is needed for review of the records

75 of 80

Agency Policy and Procedures cont.

HIT CONFIRMATIONS

    • Location of where records are kept for confirmation
    • Who shall be contacted regarding extradition matters, decisions and transportation arrangements
    • Retention and annotation of terminal-produced printouts for agency's case file

76 of 80

Agency Policy and Procedures cont.

TERMINAL EQUIPMENT

    • Identify the terminal equipment/devices, what they are and where they are located (terminals, printers and other equipment that may be in operation)
    • Procedures on how to reset, reboot, restart, or re-initialize your equipment
    • Who to call when service is needed

77 of 80

Terminal Equipment Management

INSTALLATION

    • Requests for additional terminals need to be emailed to the Control Terminal at dci-controlterminal-all@wyo.gov
    • Agencies will be responsible for purchasing additional Messenger licenses

78 of 80

Terminal Equipment Management cont.

RELOCATION

    • If an agency is planning to relocate, the CT needs to be contacted

MAINTENANCE

    • Agencies are responsible for the maintenance of their terminal equipment (computers, monitors, printers, etc.)

79 of 80

Terminal Equipment Management cont.

TROUBLE REPORTING

    • All trouble reports must be made to the CT
    • The CT will evaluate the report and assist in resolution
    • If the CT can’t resolve the problem, the appropriate contacts will be made
    • If the problem is with local agency equipment, it is the responsibility of the agency to make the necessary arrangements for equipment repair
    • It is also the agency’s responsibility to ensure that security considerations are taken in accordance with the CJIS Security Policy, when a computer is taken off-site for repair

80 of 80

Terminal Equipment Management cont.

AGENCY PROCEDURES CONCERNING EQUIPMENT

    • All agencies should have written procedures that cover the following:
      • The location and identification of all terminal and associated equipment
      • Who to call for assistance and when
      • Who to call for service and when