# SP-006 Wireless- Private Network Pattern

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for deploying and managing enterprise wireless networks as trusted extensions of the corporate LAN, covering WPA2/WPA3 encryption, 802.1X certificate-based authentication, rogue access point detection, and wireless-specific incident response.
Use when: Apply this pattern when providing wireless network access to corporate or organisational network resources from managed locations such as offices, campuses, and facilities where the organisation controls the wireless infrastructure. This is appropriate when the organisation manages the endpoint devices connecting to the network and can enforce configuration requirements including certificate enrollment and 802.1X...
Not when: This pattern is not appropriate for environments where guest or unmanaged device access is the primary use case -- use a separate guest network or the Wireless Public Hotspot pattern instead.

## Controls (19, NIST SP 800-53 ids)
- Critical (5): AC-18, CA-07, IA-02, IA-03, SC-08
- Important (8): AC-19, AU-02, CA-02, IR-04, IR-05, RA-05, SC-09, SC-13
- Standard (6): AT-01, AT-03, AT-04, IR-02, IR-06, IR-07
- Withdrawn in SP 800-53 Rev 5: SC-09 (now in SC-08)

## What each critical control mitigates (5)
- AC-18 Wireless Access Restrictions: T-WP-003, T-WP-006, T-WP-007
- CA-07 Continuous Monitoring: T-WP-002, T-WP-005, T-WP-006, T-WP-007, T-WP-008, T-WP-009
- IA-02 User Identification And Authentication: T-WP-003, T-WP-004
- IA-03 Device Identification And Authentication: T-WP-003, T-WP-004, T-WP-006
- SC-08 Transmission Integrity: T-WP-001

## Threats and the controls that mitigate them (10)
- T-WP-001 Wireless Eavesdropping and Traffic Interception: SC-08, SC-09, SC-13
- T-WP-002 Rogue Access Point and Evil Twin Attacks: CA-07, RA-05, IR-04, IR-05
- T-WP-003 Unauthorised Network Access via Wireless: AC-18, IA-02, IA-03, AC-19
- T-WP-004 Credential Theft and Authentication Bypass: IA-02, IA-03, SC-13
- T-WP-005 Deauthentication and Denial-of-Service Attacks: CA-07, IR-04, IR-05, IR-06
- T-WP-006 Device Spoofing and Impersonation: IA-03, AC-18, CA-07
- T-WP-007 Lateral Movement from Compromised Wireless Client: AC-18, CA-07, IR-04, RA-05
- T-WP-008 Misconfigured or Unpatched Access Point Firmware: RA-05, CA-02, CA-07
- T-WP-009 Insider Deploying Unauthorised Wireless Infrastructure: CA-07, AT-01, AT-03, IR-04
- T-WP-010 Delayed Detection and Response to Wireless Incidents: IR-02, IR-04, IR-05, IR-06, IR-07

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-006/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-006/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 22 KB: /api/v1/patterns/SP-006
- Page for people: /patterns/sp-006/
- Related: SP-001 Client Module; SP-007 Wireless Public Hotspot Pattern; SP-015 Secure Remote Working; SP-016 DMZ Module; SP-024 iPhone Pattern; SP-025 Advanced Monitoring and Detection

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
