An officer calls: the dispatch workstation that shows criminal justice information has locked up, and the nearest technician is across the county. The fix is a two-minute remote session. Under CJIS Security Policy v6.0, control SC-13, the cryptography protecting that information in transit outside a physically secure location has to run through a FIPS 140-3 validated module. A consumer screen-share tool cannot answer that question; it just moves the risk onto your agency.
What the requirement asks of remote access, and what Lavawall does
| The control | Lavawall® in FIPS mode |
|---|---|
| Validated session cryptography | Remote sessions run over TLS performed by FIPS 140-3 validated cryptographic modules, not an ad-hoc library. |
| Strong access control | The console can require a FIPS 140-3 validated login key before a technician can start a session, checked against the NIST CMVP list. |
| Auditability | Every session is logged with who connected, to which device, and when, which is the evidence a CJIS auditor asks for. |
| Reach without weakening | Control Windows, macOS, and Linux, including from a phone browser, without dropping to a weaker channel to do it. |
Why this matters more than the feature list
Remote access is where most agencies quietly fall out of compliance, because the tool that is easiest to grab in a hurry is rarely the one that can name its cryptographic module. Lavawall® is one platform: the same console that runs your patching, monitoring, and GRC also runs the remote session, so the FIPS posture is consistent instead of stitched together from separate vendors. See the full remote support capability for what the sessions can do.
Related
Frequently asked
- Does the remote session itself use FIPS 140-3 cryptography?
- In its FIPS configuration, yes: the session's TLS is performed by FIPS 140-3 validated cryptographic modules. ThreeShield documents the specific module and certificate for your deployment.
- Can I require a FIPS-validated key before a technician connects?
- Yes. The console can enforce FIPS 140-3 validated login authenticators, checked against the NIST CMVP list at registration and every login, so only a technician with a compliant key can start a session.