STIGQter STIGQter: STIG Summary: Network WLAN Controller Platform Security Technical Implementation Guide Version: 7 Release: 3 Benchmark Date: 27 Apr 2023:

WLAN components must be FIPS 140-2 or FIPS 140-3 certified and configured to operate in FIPS mode.

DISA Rule

SV-243235r891326_rule

Vulnerability Number

V-243235

Group Title

SRG-NET-000151

Rule Version

WLAN-NW-000600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Use WLAN equipment that is FIPS 140-2/3 (CMVP) certified. Configure the component to operate in FIPS mode.

Check Contents

Review the WLAN equipment specification and verify it is FIPS 140-2/3 (CMVP) certified for data in transit, including authentication credentials. Verify the component is configured to operate in FIPS mode.

If the WLAN equipment is not is FIPS 140-2/3 (CMVP) certified or is not configured to operate in FIPS mode, this is a finding.

Vulnerability Number

V-243235

Documentable

False

Rule Version

WLAN-NW-000600

Severity Override Guidance

Review the WLAN equipment specification and verify it is FIPS 140-2/3 (CMVP) certified for data in transit, including authentication credentials. Verify the component is configured to operate in FIPS mode.

If the WLAN equipment is not is FIPS 140-2/3 (CMVP) certified or is not configured to operate in FIPS mode, this is a finding.

Check Content Reference

M

Target Key

5398