← Controls / AC

AC-18 Wireless Access

Access Control

Low Moderate High

Description

a. Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and b. Authorize each type of wireless access to the system prior to allowing such connections.

Supplemental Guidance

Wireless technologies include microwave, packet radio (ultra-high frequency or very high frequency), 802.11x, and Bluetooth. Wireless networks use authentication protocols that provide authenticator protection and mutual authentication.

Changes from Rev 4

Control text drops 'usage restrictions' Adds 'for each type of' wireless access

Enhancements (4)

What NIST adds to this control. Select one to read its statement.

AC-18(01) Authentication and Encryption ModerateHigh

Protect wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption.

AC-18(03) Disable Wireless Networking ModerateHigh

Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.

AC-18(04) Restrict Configurations by Users High

Identify and explicitly authorize users allowed to independently configure wireless networking capabilities.

AC-18(05) Antennas and Transmission Power Levels High

Select radio antennas and calibrate transmission power levels to reduce the probability that signals from wireless access points can be received outside of organization-controlled boundaries.

Withdrawn by NIST:

  • AC-18(02) Monitoring Unauthorized Connections, now in SI-04

Patterns that use this control (4)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.14A.8.20

COBIT 2019

DSS05

NIST CSF 2.0

PR.AA-05

PCI DSS v4.0.1

11.2

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

BSI IT-Grundschutz

ORP.4

ANSSI

Hygiene.25Hygiene.26SecNumCloud.14.3

FINMA Circular 2023/1

IV.B.d(59)IV.C(62)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(a)Art.32(1)(b)

EU DORA

Art.9(4)(a)

RBI CSF

Annex1.4ITGRCA.19

FISC Security Guidelines

FISC.T3FISC.T10

HKMA TM-E-1

TME1.8.5

MLPS 2.0

8.1.3.18.38.5

SAMA CSF

3.13.3

UAE IA

T8T9

CBB TM

TM-6TM-8

Qatar NIA

ACCS

CBE CSF

CTO-6

BoM CTRM

3.2

FFIEC IS

II.C.9II.C.15(c)

HIPAA Security Rule

§164.312(e)(1)

ECB CROE

CROE.2.3.5

BOT Cyber Resilience

Ch2.4

CMMC 2.0

AC

PCI PTS v6

J

Solvency II

EIOPA-ICT-4.6

Lloyd's Minimum Standards

MS8.9

HITRUST CSF v11

01.b

ISO 17799 (legacy)

11.4.211.7.111.7.2

COBIT 4.1 (legacy)

None.