Check: SRG-MPOL-016
Mobile Policy SRG:
SRG-MPOL-016
(in version v1 r2)
Title
The organization must establish implementation guidance for wireless access. (Cat II impact)
Discussion
Wireless technologies include, but are not limited to, microwave, satellite, packet radio (UHF/VHF), Wi-Fi, and Bluetooth. Wireless networks present similar security risks to those of a wired network, and since the open airwaves are the communications medium for wireless technology, an entirely new set of risks are introduced. Implementing wireless computing and networking capabilities in accordance with the organization defined wireless policy, and allowing only authorized and qualified personnel to configure wireless services, greatly reduces vulnerabilities.
Check Content
Review the organization's access control policy, security procedures addressing wireless implementation, and other relevant documents to ensure the organization has established clear guidance for the implementation of wireless access. If the site does not have clear guidance established for implementation, this is a finding.
Fix Text
Establish clear guidance for the implementation of wireless access within the organization's boundaries/enclave/area of responsibility.
Additional Identifiers
Rule ID:
Vulnerability ID: V-35934
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001439 |
The organization establishes implementation guidance for wireless access. |
Controls
Number | Title |
---|---|
AC-18 |
Wireless Access |