IDAPA 11.10.01.024

Ilets Security

Last amended: 2026Year: 2026Length: 735 wordsOfficial source
01. General Policy. The data stored in the ILETS, NCIC, and other criminal justice information system files is documented criminal justice information. This information must be protected to ensure its integrity and its correct, legal and efficient storage, dissemination and use. It is incumbent upon an agency accessing ILETS directly, or another system that has access to the ILETS network, to implement the procedures necessary to make the access device secure from any unauthorized use and to ensure ILETS is not subject to a malicious disruption of service. IDAHO ADMINISTRATIVE CODE IDAPA 11.10.01 – Rules Governing Idaho Public Idaho State Police Safety & Security Information System Section 024 Page 8 ILETS access agencies must participate in ILETS training and compliance activities to ensure that all agency personnel authorized to access the ILETS network are instructed in the proper use and dissemination of the information and that appropriate agency personnel are aware of security requirements and of the dangers to network integrity. ILETS may impose more stringent or additional protection measures than outlined in this document. ILETS retains the authority to disconnect an access agency or network connection when serious security threats and vulnerabilities are detected. (7-1-26) 02. Definitions. The following is a list of terms and their meanings as used in the ILETS security rule: (3-23-22) a. ILETS Security Officer (ISO) is the department staff member designated by the executive officer to monitor and enforce agency compliance with site and network security requirements. This position contains additional responsibilities as defined in the CJIS Security Policy as CJIS Systems Agency Information Security Officer. (7-1-26) b. Peer networks are interfaces between cooperative governmental agencies in Idaho where none of the participating entities exercise administrative or management control over any other participating entity. (7-1-26) c. Untrusted system is any system or series of systems that does not meet the compliance requirements of ILETS, Nlets, CJIS Security Policy, and/or are not authorized for access to ILETS information. (7-1-26) 03. Direct Access Agency Agreements. To ensure agencies having computer interface capabilities to ILETS are fully aware of their duties and of the consequences of failure to carry out those duties, a written and binding Direct Access Agency Agreement must exist between ILETS and all direct access agencies. This agreement will clarify that the direct access agency is equally responsible for actions by secondary and affiliated systems connected through their site to ILETS. Direct access agencies must put in place similar subsidiary security agreements with secondary and affiliated systems to protect its network and ILETS. (7-1-26) 04. ILETS Security Officer. The ILETS Security Officer is responsible for the following duties: (3-23-22) a. Make available to user agencies copies of ILETS security policies and guidelines; (7-1-26) b. Communicating to user agencies information regarding current perceived security threats and providing recommended measures to address the threats; (3-23-22) c. Monitoring use of the ILETS systems either in response to information about a specific threat, or generally because of a perceived situation; (7-1-26) d. Directing an direct access agency, through its appropriate contact, to rectify any compliance findings; (7-1-26) e. When an agency is unable or unwilling to co-operate, reporting the issue to the executive officer and initiating escalated sanctions pursuant to IDAPA 11.10.01 section 28; and (7-1-26) f. Provide support and coordination for investigations into breaches of security. (3-23-22) 05. Agency Security Contacts. A terminal agency coordinator shall serve as that agency’s security contact for ILETS, unless another individual is specifically selected for this purpose and approved by the ILETS Security Officer. ILETS primary sites shall ensure the agency’s security contact, or another person or position designated in an incident contingency plan, can be contacted by the ILETS security officer at any time. (3-23-22) 06. Peer Networks. The security responsibilities of the operators of peer networks connected to ILETS, with respect to their user organizations, are parallel to those of ILETS user organizations in respect to their individual users. The ILETS Security Officer shall ensure that a written agreement exists between ILETS and an interface agency, signed by the agency heads, that embodies these principles. (3-23-22) IDAHO ADMINISTRATIVE CODE IDAPA 11.10.01 – Rules Governing Idaho Public Idaho State Police Safety & Security Information System Section 027 Page 9 07. Network/Physical/Personnel Security Standards. Are established through the incorporation by reference of the CJIS Security Policy. (7-1-26) 025. -- 026. (RESERVED) 027. MISUSE OF THE ILETS SYSTEM AND/OR DERIVED INFORMATION Refer to the ILETS Manual. (7-1-26)
IDAPA 11.10.01.024: Ilets Security | Justis AI