The organization must establish usage restrictions for wireless access.

From Mobile Policy Security Requirements Guide

Part of SRG-MPOL-010

Associated with: CCI-001438

SV-47240r1_rule The organization must establish usage restrictions for wireless access.

Vulnerability discussion

Wireless security has additional vulnerability because of transmission over an open medium accessible by all, yielding a broader threat profile. Without a methodology for the deployment and usage of wireless devices and access, security of the infrastructure and data cannot be assured. Wireless technologies include, but are not limited to, microwave, satellite, packet radio (UHF/VHF), Wi-Fi, and Bluetooth. Wireless networks present similar security risks to those of a wired network, and since the open airwaves are the communications medium for wireless technology, an entirely new set of risks are introduced. Implementing wireless computing and networking capabilities in accordance with the organization defined wireless policy, and allowing only authorized and qualified personnel to configure wireless services, greatly reduces vulnerabilities.

Check content

Review the organization's access control policy, security procedures addressing wireless usage restrictions, and other relevant documents. The objective is to ensure the organization has defined usage restrictions for all wireless access. If the organization has not established usage restrictions, this is a finding.

Fix text

Establish a usage restrictions policy for wireless access within the organization's boundaries/enclave/area of responsibility.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer