Skip to content
ControlVerdict
AC.L2-3.1.17addresses
AC.L2-3.1.17Wireless Access Protection
Protect wireless access using authentication and encryption.
  • [a]

    wireless access to the system is protected using authentication; and
  • [b]

    wireless access to the system is protected using encryption.

View full control

WPA2/3-Enterprise with certs; no PSK on CUI-capable SSIDs

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Wireless Access Protection objectives.

Authentication + encryption. Corp SSID uses WPA2/3-Enterprise with RADIUS. PSK SSIDs are forbidden for any VLAN that can reach CUI. Management frames protected where hardware supports it.

Maintenance. Annual wireless security assessment; disable legacy protocols (WEP/TKIP) if reintroduced by defaults after upgrades.

Accepted gap. IoT sensors use a PSK SSID on an air-gapped building VLAN with no route to CUI systems.

What the evidence looks like

  • WLC SSID security settings export
  • RADIUS auth success logs sample
  • IoT PSK SSID isolation evidence

Environment

Same wireless plant as 3.1.16.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.