# SP-007 Wireless- Public Hotspot Pattern

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for safely accessing corporate network resources from untrusted public wireless hotspots, using VPN tunnels, personal firewalls, strong authentication, and endpoint hardening to protect data in transit and at rest.
Use when: Apply this pattern when corporate users need to access organisational network resources from wireless networks not controlled by the organisation: hotels, airports, conference venues, coffee shops, co-working spaces, or any other public or semi-public WiFi. This pattern is appropriate when the organisation cannot guarantee the security of the wireless infrastructure and must treat the entire local network as hostile.
Not when: This pattern is not necessary when connecting from the organisation's own managed private wireless network (use the Wireless Private Network pattern instead).

## Controls (17, NIST SP 800-53 ids)
- Critical (5): AC-19, IA-02, SC-08, SC-09, SC-13
- Important (6): AU-02, CA-02, CA-07, IR-04, IR-05, RA-05
- Standard (6): AT-01, AT-03, AT-04, IR-02, IR-06, IR-07
- Withdrawn in SP 800-53 Rev 5: SC-09 (now in SC-08)

## What each critical control mitigates (5)
- AC-19 Access Control For Portable And Mobile Devices: T-PH-005, T-PH-006, T-PH-007, T-PH-008
- IA-02 User Identification And Authentication: T-PH-002, T-PH-004
- SC-08 Transmission Integrity: T-PH-001, T-PH-002, T-PH-003
- SC-09 Transmission Confidentiality: T-PH-001, T-PH-003, T-PH-007
- SC-13 Use Of Cryptography: T-PH-001, T-PH-002, T-PH-004, T-PH-008

## Threats and the controls that mitigate them (10)
- T-PH-001 Network Eavesdropping on Untrusted Wireless: SC-08, SC-09, SC-13
- T-PH-002 Man-in-the-Middle Attack via ARP Spoofing or DNS Hijacking: SC-08, SC-13, IA-02
- T-PH-003 Evil Twin Access Point Impersonation: SC-08, SC-09, AT-03, CA-07
- T-PH-004 Credential Theft and Replay via Captive Portal Spoofing: IA-02, SC-13, AT-03
- T-PH-005 Network-Based Attack from Co-Located Hotspot Users: AC-19, RA-05, IR-04
- T-PH-006 Endpoint Compromise on Hostile Network: AC-19, RA-05, CA-07, IR-04
- T-PH-007 Data Leakage via Split Tunnel or VPN Bypass: AC-19, SC-09, CA-07, AU-02
- T-PH-008 Device Theft or Physical Compromise While Mobile: AC-19, SC-13, IR-04, IR-06
- T-PH-009 Unpatched or Non-Compliant Endpoint Connecting via VPN: RA-05, CA-02, CA-07
- T-PH-010 Delayed Incident Detection for Remote Workers: IR-02, IR-04, IR-05, IR-06, IR-07

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-007/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-007/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 22 KB: /api/v1/patterns/SP-007
- Page for people: /patterns/sp-007/
- Related: SP-001 Client Module; SP-006 Wireless Private Network Pattern; SP-015 Secure Remote Working; SP-016 DMZ Module; SP-024 iPhone Pattern; SP-025 Advanced Monitoring and Detection

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
