| Checked | Name | Title |
|---|
| ☐ | SV-243207r720076_rule | WLAN SSIDs must be changed from the manufacturer's default to a pseudo random word that does not identify the unit, base, organization, etc. |
| ☐ | SV-243208r817084_rule | The WLAN inactive/idle session timeout must be set for 30 minutes or less. |
| ☐ | SV-243209r720082_rule | WLAN components must be Wi-Fi Alliance certified with WPA2 or WPA3. |
| ☐ | SV-243210r891317_rule | WLAN components must be FIPS 140-2 or FIPS 140-3 certified and configured to operate in FIPS mode. |
| ☐ | SV-243211r856608_rule | WLAN signals must not be intercepted outside areas authorized for WLAN access. |
| ☐ | SV-243212r720091_rule | The WLAN access point must be configured for Wi-Fi Alliance WPA2 or WPA3 security. |
| ☐ | SV-243213r720094_rule | DoD Components providing guest WLAN access (internet access only) must use separate WLAN or logical segmentation of the enterprise WLAN (e.g., separate service set identifier [SSID] and virtual LAN) or DoD network. |
| ☐ | SV-243214r720097_rule | The network device must be configured to only permit management traffic that ingresses and egresses the out-of-band management (OOBM) interface. |
| ☐ | SV-243215r856609_rule | The network device must not be configured to have any feature enabled that calls home to the vendor. |