AC-18: Wireless Access

Control Family:

Access Control

CSF v1.1 References:

CSF v2.0 References:

PF v1.0 References:

Threats Addressed:

Baselines:

Previous Version:

Control Statement

  1. Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and
  2. Authorize each type of wireless access to the system prior to allowing such connections.

Supplemental Guidance

Wireless technologies include microwave, packet radio (ultra-high frequency or very high frequency), 802.11x, and Bluetooth. Wireless networks use authentication protocols that provide authenticator protection and mutual authentication.

OT Discussion

When OT cannot implement any or all of the components of this control, the organization employs other mechanisms or procedures as compensating controls in accordance with the general tailoring guidance.

Control Enhancements

AC-18(1): Authentication and Encryption

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Protect wireless access to the system using authentication of [Assignment (one or more): users, devices] and encryption.

AC-18(3): Disable Wireless Networking

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.

AC-18(5): Antennas and Transmission Power Levels

Baseline(s):

  • High
  • OT High (SP 800-82r3)

Select radio antennas and calibrate transmission power levels to reduce the probability that signals from wireless access points can be received outside of organization-controlled boundaries.