SC-28 Encryption at Rest: Same Cloud Provider, Different Key Custody
Two agencies. Same checklist answer: CJI at rest is encrypted in accordance with SC-28. Both used the same cloud provider. Both cited the provider's encryption documentation. Both rated themselves compliant.
The auditor asked who held the decryption keys.
Agency A could not answer definitively. The provider encrypted the data — that was documented in the service agreement and the provider's compliance page. The encryption standard was AES-256. Whether the provider held the keys, whether the agency held the keys, and who at the provider could decrypt stored data — none of that had been formally established or documented.
Agency B had addressed key management explicitly in the service agreement: the agency held its own encryption keys, managed through a key management service the agency controlled. The provider encrypted data at rest, but the keys were not accessible to provider personnel. The agreement documented this, and the agency had a key rotation schedule and a process for key custody when personnel changed.
The auditor noted Agency A's finding: the CJIS Security Policy addresses key management directly. Individuals with access to the encryption keys can decrypt stored CJI and therefore have effective access to unencrypted CJI. If the provider holds the keys, provider personnel with key access meet the definition of persons with CJI access and must be screened, trained, and subject to the Security Addendum accordingly. Agency A had not addressed this for any provider personnel.
What the control actually requires
SC-28 read with SC-13 requires FIPS 140-3 certified cryptographic modules or FIPS-validated AES-256 with at least a 256-bit key. The September 21, 2026 deadline means FIPS 140-2 certificates are no longer acceptable.
Key custody is not a separate control — it is a consequence of how the policy defines access. CJI access is defined by the ability to view, process, or store CJI, or to decrypt data that contains it. A provider employee who holds decryption keys for an agency's encrypted CJI has that ability, regardless of whether they exercise it.
What the auditor is looking for
Documentation of the encryption configuration including the cryptographic module in use. Documentation of who holds the decryption keys. If the provider holds keys: documentation that provider personnel with key access have been screened and trained under the CJIS requirements. A service agreement that addresses key management, key rotation, and key custody on contract termination.
Encryption documentation from the provider answers one question. Key custody documentation answers a different one. Most agencies have the first. Few have addressed the second.
The common failure mode
The provider's documentation confirmed AES-256 encryption. That was treated as sufficient. The key custody question was never asked because the assumption was that encryption equals compliance. It is a reasonable assumption in most contexts. In a CJIS context, where the policy defines CJI access by the ability to decrypt rather than the intent to do so, it is not sufficient.
Written by Dr. Alexis W. Perdereaux-Weekes
DBA · CISA · CISM · CRISC · CDPSE
Founder, CJIS360 LLC
Sources: CJIS Security Policy v6.1, 06/25/2026 — SC-28 Protection of Information at Rest; SC-13 Cryptographic Protection; §1.4 Terminology Used in This Document. Note: FIPS 140-2 certificates unacceptable after September 21, 2026.