| Checked | Name | Title |
|---|
| ☐ | SV-243216r720103_rule | The site must conduct continuous wireless Intrusion Detection System (IDS) scanning. |
| ☐ | SV-243217r720106_rule | WLAN SSIDs must be changed from the manufacturer's default to a pseudo random word that does not identify the unit, base, organization, etc. |
| ☐ | SV-243218r817087_rule | The WLAN inactive/idle session timeout must be set for 30 minutes or less. |
| ☐ | SV-243219r720112_rule | WLAN components must be Wi-Fi Alliance certified with WPA2 or WPA3. |
| ☐ | SV-243220r720115_rule | WLAN must use EAP-TLS. |
| ☐ | SV-243221r891320_rule | WLAN components must be FIPS 140-2 or FIPS 140-3 certified and configured to operate in FIPS mode. |
| ☐ | SV-243222r720121_rule | WLAN EAP-TLS implementation must use certificate-based PKI authentication to connect to DoD networks. |
| ☐ | SV-243223r720124_rule | WLAN signals must not be intercepted outside areas authorized for WLAN access. |
| ☐ | SV-243224r720127_rule | Wireless access points and bridges must be placed in dedicated subnets outside the enclave's perimeter. |
| ☐ | SV-243225r720130_rule | The network device must be configured to only permit management traffic that ingresses and egresses the out-of-band management (OOBM) interface. |
| ☐ | SV-243226r720133_rule | The network device must not be configured to have any feature enabled that calls home to the vendor. |