# AC-18 Wireless Access

NIST SP 800-53 control. Family: AC Access Control. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and b. Authorize each type of wireless access to the system prior to allowing such connections.
Guidance: Wireless technologies include microwave, packet radio (ultra-high frequency or very high frequency), 802.11x, and Bluetooth. Wireless networks use authentication protocols that provide authenticator protection and mutual authentication.

## Enhancements (4)
- AC-18(01) Authentication and Encryption. Baselines: moderate, high
- AC-18(03) Disable Wireless Networking. Baselines: moderate, high
- AC-18(04) Restrict Configurations by Users. Baselines: high
- AC-18(05) Antennas and Transmission Power Levels. Baselines: high
Withdrawn by NIST: AC-18(02) (now in SI-04).
Each enhancement's statement: /api/v1/controls/AC-18?fields=enhancements

## Patterns that use it (4)
- Critical (1): SP-006 Wireless- Private Network Pattern
- Important (1): SP-023 Industrial Control Systems
- Standard (2): SP-025 Advanced Monitoring and Detection; SP-026 PCI Full Environment

## Clauses by framework (31 frameworks)
- iso_27001_2022: A.5.14, A.8.20
- cobit_2019: DSS05
- pci_dss_v4: 11.2
- nist_csf_2: PR.AA-05
- nis2: Art. 21(2)(i)
- mas_trm: 9
- bsi_grundschutz: ORP.4
- anssi: Hygiene.25, Hygiene.26, SecNumCloud.14.3
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.C(62)
- gdpr: Art.32(1)(a), Art.32(1)(b)
- dora: Art.9(4)(a)
- rbi_csf: Annex1.4, ITGRCA.19
- fisc: FISC.T3, FISC.T10
- hkma_tme1: TME1.8.5
- mlps_2: 8.1.3.1, 8.3, 8.5
- cbb_tm: TM-6, TM-8
- qatar_nia: AC, CS
- sama_csf: 3.1, 3.3
- uae_ia: T8, T9
- bom_ctrm: 3.2
- cbe_csf: CTO-6
- bot_cyber: Ch2.4
- ecb_croe: CROE.2.3.5
- ffiec_is: II.C.9, II.C.15(c)
- hipaa_sr: §164.312(e)(1)
- cmmc_2: AC
- pci_pts: J
- hitrust_csf: 01.b
- lloyds_ms: MS8.9
- solvency_ii: EIOPA-ICT-4.6
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AC-18
- Clauses only: /api/v1/controls/AC-18?fields=mappings
- Page for people: /controls/ac-18/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
