The organization must remove the wireless interface on computers with an embedded wireless system before the computer is used to transfer, receive, store, or process classified information.

From Mobile Policy Security Requirements Guide

Part of SRG-MPOL-015

Associated with: CCI-001438

SV-47249r2_rule The organization must remove the wireless interface on computers with an embedded wireless system before the computer is used to transfer, receive, store, or process classified information.

Vulnerability discussion

The majority of consumer based laptops have wireless network interface cards (NICs) integrated with the computer's motherboard. Although the system administrator may disable these embedded NICs, the user may purposely or accidentally enable the device. These devices may also inadvertently transmit ambient sound or electronic signals. Therefore, simply disabling the transmit capability is not an adequate solution for computers processing classified information. In addition, embedded wireless cards do not meet DoD security requirements for classified wireless usage.

Check content

Review the organization's policy to ensure wireless NICs are required to be removed prior to use in a classified environment. Verify the site has procedures in place to ensure laptops with wireless NICs are not used for classified data processing. Inquire about laptops/PCs used to process classified information that have embedded wireless NICs. No embedded wireless NICs are allowed, including WLAN, Bluetooth, WMAN, cellular, etc. Ensure the NIC is physically removed. Using methods such as tape or software disabling are not acceptable. Determine if the site either purchased laptops without wireless NICs (Wi-Fi, Bluetooth, WiMax, etc.) or physically removed the NICs from laptops. If the site is using embedded wireless NICs in a classified environment, this is a finding. Recommend to the DAA this is a critical finding requiring immediate action. Note: Does not apply to Communication Systems for Classified (CSfC) Wi-Fi systems.

Fix text

Remove computers with embedded wireless interfaces that cannot be removed from all classified use; these computers must not transfer, receive, store, or process classified information.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer