Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35952 | SRG-MPOL-034 | SV-47268r1_rule | Medium |
Description |
---|
Wireless technologies include, but are not limited to, microwave, satellite, packet radio (UHF/VHF), Wi-Fi, and Bluetooth. Wireless networks present similar security risks to those of a wired network, and since the open airwaves are the communications medium for wireless technology, an entirely new set of risks are introduced. Implementing wireless computing and networking capabilities in accordance with the organization defined wireless policy, and allowing only authorized and qualified personnel to configure wireless services greatly reduces vulnerabilities. For example, wireless networks use authentication protocols (e.g., EAP/TLS, PEAP), which provide credential protection and mutual authentication. |
STIG | Date |
---|---|
Mobile Policy Security Requirements Guide | 2013-01-24 |
Check Text ( C-44189r1_chk ) |
---|
Review the organization's access control policy and procedures addressing wireless implementation and usage (including restrictions); security policy; restrictions and any other associated documentation; activities related to wireless monitoring, authorization, and enforcement; information system audit records; and other relevant documents or records. Organizational personnel responsible for authorizing, monitoring or controlling the use of wireless technologies in the information system will be interviewed. The objective of the reviews and interviews is to ensure the organization enforces the requirements for wireless connections to the information system. If the organization does not enforce wireless connection requirements, this is a finding. |
Fix Text (F-40477r1_fix) |
---|
Update the organization policy to enforce the requirements for wireless connections to the information system. |