NIST IR 8523 offers practical guidance to help law-enforcement and justice agencies secure Criminal Justice Information (CJI) with multi-factor authentication (MFA). It explains why moving beyond passwords is critical, then lays out core design principles: reusing authenticators, offering multiple factor types, and minimizing shared secrets. The report also compares MFA options—local agency, state-level, VPN-integrated, or federated architectures—showing how each balances security, usability, and cost. Recommendations stress phishing-resistant authenticators, single sign-on, and phased rollouts to make adoption smoother and more effective.

| Format: |
|
| Topics: | |
| Website: | Visit Publisher Website |
| Publisher: | U.S. Department of Commerce |
| Published: | September 1, 2025 |
| License: | Public Domain |