Check: SRG-MPOL-018
Mobile Policy SRG:
SRG-MPOL-018
(in version v1 r2)
Title
The organizations wireless policy or wireless remote access policy must include information on locations CMD Wi-Fi access is approved or disapproved. (Cat III impact)
Discussion
If the policy does not include information on Wi-Fi security controls, it is more likely that the security controls will not be implemented properly. Without appropriate controls, Wi-Fi is vulnerable to a number of security breaches. These breaches could involve the interception of sensitive DoD information and the use of the device to connect to DoD networks.
Check Content
Review the site wireless security policy or wireless remote access policy. Verify it contains information on locations where CMD Wi-Fi access is approved or disapproved. The following locations will be specifically listed in the policy: - DoD/Government site-managed Wi-Fi access point connected to the NIPRNet (Enclave-NIPRNet Connected). - DoD/Government site-managed Wi-Fi access point connected to the Internet only (Internet Gateway Only Connection). - Public Wi-Fi Hotspot. - Hotel Wi-Fi Hotspot. - Home Wi-Fi network (user-managed). DoD CMD will not be used to connect to Public or Hotel Hotspots. If the site policy does not contain the required information on required CMD Wi-Fi security controls, this is a finding. Note: Applies to any Wi-Fi System.
Fix Text
Update the CMD Wi-Fi security policy to include information on locations CMD Wi-Fi access is approved or disapproved.
Additional Identifiers
Rule ID:
Vulnerability ID: V-35936
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001439 |
The organization establishes implementation guidance for wireless access. |
Controls
Number | Title |
---|---|
AC-18 |
Wireless Access |