Check: WLAN-NW-000200
Network WLAN AP-IG Platform STIG:
WLAN-NW-000200
(in versions v7 r3 through v7 r1)
Title
WLAN SSIDs must be changed from the manufacturer's default to a pseudo random word that does not identify the unit, base, organization, etc. (Cat III impact)
Discussion
An SSID identifying the unit, site, or purpose of the WLAN or that is set to the manufacturer default may cause an OPSEC vulnerability.
Check Content
Review device configuration. 1. Obtain the SSID using a wireless scanner or the AP or WLAN controller management software. 2. Verify the name is not meaningful (e.g., site name, product name, room number, etc.) and is not set to the manufacturer's default value. If the SSID does not meet the requirement listed above, this is a finding.
Fix Text
Change the SSID to a pseudo random word that does not identify the unit, base, or organization.
Additional Identifiers
Rule ID: SV-243207r720076_rule
Vulnerability ID: V-243207
Group Title: SRG-NET-000512
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |