STIGQter STIGQter: STIG Summary: Network WLAN Controller Platform Security Technical Implementation Guide Version: 7 Release: 3 Benchmark Date: 27 Apr 2023:

WLAN EAP-TLS implementation must use certificate-based PKI authentication to connect to DoD networks.

DISA Rule

SV-243236r720163_rule

Vulnerability Number

V-243236

Group Title

SRG-NET-000070

Rule Version

WLAN-NW-000700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Integrate certificate-based PKI authentication into the WLAN authentication process.

Check Contents

Interview the site ISSO and SA. Determine if the site's network is configured to require certificate-based PKI authentication before a WLAN user is connected to the network.

If certificate-based PKI authentication is not required prior to a DoD WLAN user accessing the DoD network, this is a finding.

Note: This check does not apply to medical devices. Medical devices are permitted to connect to the WLAN using pre-shared keys.

Vulnerability Number

V-243236

Documentable

False

Rule Version

WLAN-NW-000700

Severity Override Guidance

Interview the site ISSO and SA. Determine if the site's network is configured to require certificate-based PKI authentication before a WLAN user is connected to the network.

If certificate-based PKI authentication is not required prior to a DoD WLAN user accessing the DoD network, this is a finding.

Note: This check does not apply to medical devices. Medical devices are permitted to connect to the WLAN using pre-shared keys.

Check Content Reference

M

Target Key

5398