Wireless Access Protection
Practice statement
Protect wireless access using authentication and encryption.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.1.17.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(2)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
wireless access to the system is protected using authentication; and
1 example covers this
- [b]
wireless access to the system is protected using encryption.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AC.L2-3.1.17Wireless Access Protection
Protect wireless access using authentication and encryption.
[a]
wireless access to the system is protected using authentication; and[b]
wireless access to the system is protected using encryption.
WPA2/3-Enterprise with certs; no PSK on CUI-capable SSIDs
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses both Wireless Access Protection objectives.
Authentication + encryption. Corp SSID uses WPA2/3-Enterprise with RADIUS. PSK SSIDs are forbidden for any VLAN that can reach CUI. Management frames protected where hardware supports it.
Maintenance. Annual wireless security assessment; disable legacy protocols (WEP/TKIP) if reintroduced by defaults after upgrades.
Accepted gap. IoT sensors use a PSK SSID on an air-gapped building VLAN with no route to CUI systems.
What the evidence looks like
- WLC SSID security settings export
- RADIUS auth success logs sample
- IoT PSK SSID isolation evidence
Environment
Same wireless plant as 3.1.16.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.