STIGQter STIGQter: STIG Summary:

Network WLAN AP-NIPR Platform Security Technical Implementation Guide

Version: 7

Release: 3 Benchmark Date: 27 Apr 2023

CheckedNameTitle
SV-243216r720103_ruleThe site must conduct continuous wireless Intrusion Detection System (IDS) scanning.
SV-243217r720106_ruleWLAN SSIDs must be changed from the manufacturer's default to a pseudo random word that does not identify the unit, base, organization, etc.
SV-243218r817087_ruleThe WLAN inactive/idle session timeout must be set for 30 minutes or less.
SV-243219r720112_ruleWLAN components must be Wi-Fi Alliance certified with WPA2 or WPA3.
SV-243220r720115_ruleWLAN must use EAP-TLS.
SV-243221r891320_ruleWLAN components must be FIPS 140-2 or FIPS 140-3 certified and configured to operate in FIPS mode.
SV-243222r720121_ruleWLAN EAP-TLS implementation must use certificate-based PKI authentication to connect to DoD networks.
SV-243223r720124_ruleWLAN signals must not be intercepted outside areas authorized for WLAN access.
SV-243224r720127_ruleWireless access points and bridges must be placed in dedicated subnets outside the enclave's perimeter.
SV-243225r720130_ruleThe network device must be configured to only permit management traffic that ingresses and egresses the out-of-band management (OOBM) interface.
SV-243226r720133_ruleThe network device must not be configured to have any feature enabled that calls home to the vendor.