AC-18(1): Authentication and Encryption
Control Family:
Parent Control:
CSF v1.1 References:
CSF v2.0 References:
PF v1.0 References:
Threats Addressed:
Baselines:
- Moderate
- High
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- AC-18(1): Authentication And Encryption
Control Statement
Protect wireless access to the system using authentication of [Assignment (one or more): users, devices] and encryption.
Supplemental Guidance
Wireless networking capabilities represent a significant potential vulnerability that can be exploited by adversaries. To protect systems with wireless access points, strong authentication of users and devices along with strong encryption can reduce susceptibility to threats by adversaries involving wireless technologies.
OT Discussion
The implementation of authentication and encryption is driven by the OT environment. If devices and users cannot all be authenticated and encrypted due to operational or technology constraints, compensating controls include providing increased auditing for wireless access, limiting wireless access privileges to key personnel, or using AC-18 (5) to reduce the boundary of wireless access.