SV-39895r3_rule
V-30257
WLAN DoD authentication
WIR0116
CAT II
10
Integrate certificate-based PKI authentication into the WLAN authentication process.
Detailed Policy Requirements:
Certificate-based PKI authentication must be used to connect WLAN client devices to DoD networks. The certificate-based PKI authentication should directly support the WLAN EAP-TLS implementation.
At least one layer of user authentication must enforce network authentication requirements (e.g., CAC authentication) before the user is able to access DoD information resources.
Check Procedures:
Interview the site ISSO and SA. Determine if the site’s network is configured to require certificate-based PKI authentication before a WLAN user is connected to the network. If certificate-based PKI authentication is not required prior to a DoD WLAN user accessing the DoD network, this is a finding.
Note: This check does not apply to medical devices. Medical devices are permitted to connect to the WLAN using pre-shared keys.
V-30257
False
WIR0116
Detailed Policy Requirements:
Certificate-based PKI authentication must be used to connect WLAN client devices to DoD networks. The certificate-based PKI authentication should directly support the WLAN EAP-TLS implementation.
At least one layer of user authentication must enforce network authentication requirements (e.g., CAC authentication) before the user is able to access DoD information resources.
Check Procedures:
Interview the site ISSO and SA. Determine if the site’s network is configured to require certificate-based PKI authentication before a WLAN user is connected to the network. If certificate-based PKI authentication is not required prior to a DoD WLAN user accessing the DoD network, this is a finding.
Note: This check does not apply to medical devices. Medical devices are permitted to connect to the WLAN using pre-shared keys.
M
System Administrator
1538