Wireless Access

✓ LOW ✓ MODERATE ✓ HIGH
4 Enhancements 1 Overlay 13 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Wireless technologies include microwave, packet radio (ultra-high frequency or very high frequency), 802.11x, and Bluetooth. Wireless networks use authentication protocols that provide authenticator protection and mutual authentication.

Enhancements NIST SOURCE

AC-18(1) Authentication and Encryption LOW ✓ MODERATE ✓ HIGH

Protect wireless access to the system using authentication of [one of: users; devices] and encryption.

Discussion

Wireless networking capabilities represent a significant potential vulnerability that can be exploited by adversaries. To protect systems with wireless access points, strong authentication of users and devices along with strong encryption can reduce susceptibility to threats by adversaries involving wireless technologies.

Open full page for AC-18(1) →
AC-18(2) Monitoring Unauthorized Connections WITHDRAWN

Withdrawn. Incorporated into SI-4.

AC-18(3) Disable Wireless Networking LOW ✓ MODERATE ✓ HIGH

Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.

Discussion

Wireless networking capabilities that are embedded within system components represent a significant potential vulnerability that can be exploited by adversaries. Disabling wireless capabilities when not needed for essential organizational missions or functions can reduce susceptibility to threats by adversaries involving wireless technologies.

Open full page for AC-18(3) →
AC-18(4) Restrict Configurations by Users LOW MODERATE ✓ HIGH

Identify and explicitly authorize users allowed to independently configure wireless networking capabilities.

Discussion

Organizational authorizations to allow selected users to configure wireless networking capabilities are enforced, in part, by the access enforcement mechanisms employed within organizational systems.

Open full page for AC-18(4) →
AC-18(5) Antennas and Transmission Power Levels LOW MODERATE ✓ HIGH

Select radio antennas and calibrate transmission power levels to reduce the probability that signals from wireless access points can be received outside of organization-controlled boundaries.

Discussion

Actions that may be taken to limit unauthorized use of wireless communications outside of organization-controlled boundaries include reducing the power of wireless transmissions so that the transmissions are less likely to emit a signal that can be captured outside of the physical perimeters of the organization, employing measures such as emissions security to control wireless emanations, and using directional or beamforming antennas that reduce the likelihood that unintended receivers will be able to intercept signals. Prior to taking such mitigating actions, organizations can conduct periodic wireless surveys to understand the radio frequency profile of organizational systems as well as other systems that may be operating in the area.

Open full page for AC-18(5) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AC-18 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. configuration requirements are established for each type of wireless access;
  2. connection requirements are established for each type of wireless access;
  3. implementation guidance is established for each type of wireless access;
  4. each type of wireless access to the system is authorized prior to allowing such connections.

Examine

[SELECT FROM: Access control policy; procedures addressing wireless access implementation and usage (including restrictions); configuration management plan; system design documentation; system configuration settings and associated documentation; wireless access authorizations; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with responsibilities for managing wireless access connections; organizational personnel with information security responsibilities].

Test

[SELECT FROM: Wireless access management capability for the system].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1) (3)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (3) (4) (5)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AC-18. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Access control policy
  • system security plan

Configuration

  • configuration management plan
  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Wireless access management capability for the system

Other Records

  • procedures addressing wireless access implementation and usage (including restrictions)
  • wireless access authorizations
  • system audit records
  • other relevant documents or records