Check: WIR-SPP-010
Smartphone Policy:
WIR-SPP-010
(in version v1 r8)
Title
The site wireless policy or wireless remote access policy must include information on required smartphone/tablet Wi-Fi security controls. (Cat III impact)
Discussion
If the policy does not include information on Wi-Fi security controls, then it is more likely that the security controls will not be implemented properly. Wi-Fi is vulnerable to a number of security breaches without appropriate controls. These breaches could involve the interception of sensitive DoD information and the use of the device to connect to DoD networks.
Check Content
Detailed Policy Requirements: -The site wireless security policy or wireless remote access policy shall include information on locations where smartphone/tablet Wi-Fi access is approved or disapproved. The following locations will be specifically listed in the policy: -Site-managed Wi-Fi access point connected to the NIPRNet (Enclave-NIPRNet Connected). -Site-managed Wi-Fi access point connected to the Internet only (Internet Gateway Only Connection). -Public Wi-Fi Hotspot. -Hotel Wi-Fi Hotspot. -Home Wi-Fi network (user managed). Note: DoD smartphones will not be used to connect to Public or Hotel Hotspots. Check Procedures: Interview the IAO. Review the site policy. Verify it contains the required information. Mark as a finding if site policy does not contain the required information.
Fix Text
Smartphone Wi-Fi security policy includes required content.
Additional Identifiers
Rule ID: SV-30703r4_rule
Vulnerability ID: V-24966
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |