AC.L2-3.1.17Wireless Access Protection
Protect wireless access using authentication and encryption.
[a]
wireless access to the system is protected using authentication; and[b]
wireless access to the system is protected using encryption.
WPA2/3-Enterprise with certs; no PSK on CUI-capable SSIDs
Implementation
AO coverage. Addresses both Wireless Access Protection objectives.
Authentication + encryption. Corp SSID uses WPA2/3-Enterprise with RADIUS. PSK SSIDs are forbidden for any VLAN that can reach CUI. Management frames protected where hardware supports it.
Maintenance. Annual wireless security assessment; disable legacy protocols (WEP/TKIP) if reintroduced by defaults after upgrades.
Accepted gap. IoT sensors use a PSK SSID on an air-gapped building VLAN with no route to CUI systems.
What the evidence looks like
- WLC SSID security settings export
- RADIUS auth success logs sample
- IoT PSK SSID isolation evidence
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.