STIGQter STIGQter: STIG Summary: Network WLAN AP-IG Platform Security Technical Implementation Guide Version: 7 Release: 3 Benchmark Date: 27 Apr 2023:

The WLAN access point must be configured for Wi-Fi Alliance WPA2 or WPA3 security.

DISA Rule

SV-243212r720091_rule

Vulnerability Number

V-243212

Group Title

SRG-NET-000063

Rule Version

WLAN-NW-000900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the access point for WPA2 (or WPA3) authentication, confidentiality, and integrity services.

In the case of WPA2 (Personal), this action will require the selection of a strong passcode or passphrase.

In the case of WPA2 (Enterprise), this action will require the organization to deploy RADIUS or equivalent authentication services on a separate server.

In cases in which the access point does not support WPA2/WPA3, the organization will need to procure new equipment.

Check Contents

Verify the access point is configured for either WPA2/WPA3 (Enterprise) or WPA2/WPA3 (Personal) authentication. The procedure for performing this review will vary depending on the AP model. Have the SA show the configuration setting.

If the access point is not configured with either WPA2 or WPA3 security, this is finding.

Vulnerability Number

V-243212

Documentable

False

Rule Version

WLAN-NW-000900

Severity Override Guidance

Verify the access point is configured for either WPA2/WPA3 (Enterprise) or WPA2/WPA3 (Personal) authentication. The procedure for performing this review will vary depending on the AP model. Have the SA show the configuration setting.

If the access point is not configured with either WPA2 or WPA3 security, this is finding.

Check Content Reference

M

Target Key

5395