UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The organization must enforce requirements for wireless connections to the information system.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35952 SRG-MPOL-034 SV-47268r1_rule Medium
Description
Wireless technologies include, but are not limited to, microwave, satellite, packet radio (UHF/VHF), Wi-Fi, and Bluetooth. Wireless networks present similar security risks to those of a wired network, and since the open airwaves are the communications medium for wireless technology, an entirely new set of risks are introduced. Implementing wireless computing and networking capabilities in accordance with the organization defined wireless policy, and allowing only authorized and qualified personnel to configure wireless services greatly reduces vulnerabilities. For example, wireless networks use authentication protocols (e.g., EAP/TLS, PEAP), which provide credential protection and mutual authentication.
STIG Date
Mobile Policy Security Requirements Guide 2013-01-24

Details

Check Text ( C-44189r1_chk )
Review the organization's access control policy and procedures addressing wireless implementation and usage (including restrictions); security policy; restrictions and any other associated documentation; activities related to wireless monitoring, authorization, and enforcement; information system audit records; and other relevant documents or records. Organizational personnel responsible for authorizing, monitoring or controlling the use of wireless technologies in the information system will be interviewed. The objective of the reviews and interviews is to ensure the organization enforces the requirements for wireless connections to the information system. If the organization does not enforce wireless connection requirements, this is a finding.
Fix Text (F-40477r1_fix)
Update the organization policy to enforce the requirements for wireless connections to the information system.