STIGQter STIGQter: STIG Summary: Network WLAN AP-NIPR Platform Security Technical Implementation Guide Version: 7 Release: 3 Benchmark Date: 27 Apr 2023:

Wireless access points and bridges must be placed in dedicated subnets outside the enclave's perimeter.

DISA Rule

SV-243224r720127_rule

Vulnerability Number

V-243224

Group Title

SRG-NET-000512

Rule Version

WLAN-NW-001100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove wireless network devices with direct connections to an enclave network. If feasible, reconfigure network connections to isolate the WLAN infrastructure from the enclave network, separating them with a firewall or equivalent protection.

Check Contents

Review network architecture with the network administrator.

1. Verify compliance by inspecting the site network topology diagrams.
2. Since many network diagrams are not kept up to date, walk through the connections with the network administrator using network management tools or diagnostic commands to verify the diagrams are current.

If the site's wireless infrastructure, such as access points and bridges, is not isolated from the enclave network, this is a finding.

Vulnerability Number

V-243224

Documentable

False

Rule Version

WLAN-NW-001100

Severity Override Guidance

Review network architecture with the network administrator.

1. Verify compliance by inspecting the site network topology diagrams.
2. Since many network diagrams are not kept up to date, walk through the connections with the network administrator using network management tools or diagnostic commands to verify the diagrams are current.

If the site's wireless infrastructure, such as access points and bridges, is not isolated from the enclave network, this is a finding.

Check Content Reference

M

Target Key

5396