About this program
Office Wi-Fi quick audit — segmentation, encryption, guest network and rogue AP detection.
Risks addressed
- High Guest network bridges into corporate VLAN
- Medium Pre-shared key reused for years
- High Rogue AP plugged into the corporate network
Controls (6)
-
Corporate SSID uses 802.1X (EAP-TLS / PEAP)
HighThis control requires that the corporate wireless network uses 802.1X authentication with strong Extensible Authentication Protocol (EAP) methods—specifically EAP-TLS (certificate-based) or PEAP (Protected EAP with username/password over TLS tunnel). 802.1X provides per-user or per-device authentication before granting network access, replacing…
How to test + evidence
Testing procedure: No PSK on the corporate SSID — every user authenticates via RADIUS/IdP.
Evidence to collect: WLC config.
-
Guest SSID isolated from corporate VLAN
CriticalThis control enforces logical network segmentation between the guest wireless SSID and the corporate VLAN infrastructure, ensuring that devices connected to the guest network cannot directly communicate with internal corporate systems. Implementation typically involves configuring wireless access points or controllers…
How to test + evidence
Testing procedure: Guest network on separate VLAN with internet-only egress; no internal routing.
Evidence to collect: VLAN diagram + ACL export.
-
WPA3 (or WPA2-Enterprise) only
HighThis control mandates the exclusive use of WPA3 or WPA2-Enterprise encryption protocols for all wireless networks. WPA3 provides stronger cryptographic protection through Simultaneous Authentication of Equals (SAE) and forward secrecy, while WPA2-Enterprise requires individual user authentication via 802.1X/RADIUS rather than…
How to test + evidence
Testing procedure: No WPA / WPA2-Personal on production. WPA3 preferred.
Evidence to collect: WLC SSID config.
-
Rogue AP detection enabled
MediumRogue Access Point (AP) detection is a wireless security control that continuously monitors the radio frequency spectrum to identify unauthorized wireless access points operating within or near the organization's facilities. The system compares detected APs against an inventory of known,…
How to test + evidence
Testing procedure: WIPS / rogue AP detection on the controller flagging unknown SSIDs.
Evidence to collect: WIPS alerts last 30 days.
-
Per-user keying / MAC filtering for IoT
MediumPer-user keying and MAC filtering for IoT restricts network access to authorized IoT devices by binding unique cryptographic keys or hardware MAC addresses to individual user accounts or device identities. Each device is authenticated using a distinct credential set rather…
How to test + evidence
Testing procedure: IoT devices on their own SSID + VLAN with restricted egress.
Evidence to collect: IoT segmentation map.
-
Quarterly Wi-Fi survey
LowA quarterly Wi-Fi survey systematically identifies all wireless access points, SSIDs, and radio signals within and around organizational facilities using spectrum analyzers, Wi-Fi scanning tools, or site survey software. The survey detects unauthorized rogue access points, validates authorized AP configurations,…
How to test + evidence
Testing procedure: Coverage / interference / rogue survey at least quarterly.
Evidence to collect: Most recent survey report.