Skip to main content

Pro audit program · v1.0

Wi-Fi Security Audit

Office Wi-Fi quick audit — segmentation, encryption, guest network and rogue AP detection.

  • General target area
  • NIST CSF framework
  • 6 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Office Wi-Fi quick audit — segmentation, encryption, guest network and rogue AP detection.

Risks addressed

  • High Guest network bridges into corporate VLAN
  • Medium Pre-shared key reused for years
  • High Rogue AP plugged into the corporate network

Controls (6)

  1. Corporate SSID uses 802.1X (EAP-TLS / PEAP)

    High

    This control requires that the corporate wireless network uses 802.1X authentication with strong Extensible Authentication Protocol (EAP) methods—specifically EAP-TLS (certificate-based) or PEAP (Protected EAP with username/password over TLS tunnel). 802.1X provides per-user or per-device authentication before granting network access, replacing…

    How to test + evidence

    Testing procedure: No PSK on the corporate SSID — every user authenticates via RADIUS/IdP.

    Evidence to collect: WLC config.

  2. Guest SSID isolated from corporate VLAN

    Critical

    This control enforces logical network segmentation between the guest wireless SSID and the corporate VLAN infrastructure, ensuring that devices connected to the guest network cannot directly communicate with internal corporate systems. Implementation typically involves configuring wireless access points or controllers…

    How to test + evidence

    Testing procedure: Guest network on separate VLAN with internet-only egress; no internal routing.

    Evidence to collect: VLAN diagram + ACL export.

  3. WPA3 (or WPA2-Enterprise) only

    High

    This control mandates the exclusive use of WPA3 or WPA2-Enterprise encryption protocols for all wireless networks. WPA3 provides stronger cryptographic protection through Simultaneous Authentication of Equals (SAE) and forward secrecy, while WPA2-Enterprise requires individual user authentication via 802.1X/RADIUS rather than…

    How to test + evidence

    Testing procedure: No WPA / WPA2-Personal on production. WPA3 preferred.

    Evidence to collect: WLC SSID config.

  4. Rogue AP detection enabled

    Medium

    Rogue Access Point (AP) detection is a wireless security control that continuously monitors the radio frequency spectrum to identify unauthorized wireless access points operating within or near the organization's facilities. The system compares detected APs against an inventory of known,…

    How to test + evidence

    Testing procedure: WIPS / rogue AP detection on the controller flagging unknown SSIDs.

    Evidence to collect: WIPS alerts last 30 days.

  5. Per-user keying / MAC filtering for IoT

    Medium

    Per-user keying and MAC filtering for IoT restricts network access to authorized IoT devices by binding unique cryptographic keys or hardware MAC addresses to individual user accounts or device identities. Each device is authenticated using a distinct credential set rather…

    How to test + evidence

    Testing procedure: IoT devices on their own SSID + VLAN with restricted egress.

    Evidence to collect: IoT segmentation map.

  6. Quarterly Wi-Fi survey

    Low

    A quarterly Wi-Fi survey systematically identifies all wireless access points, SSIDs, and radio signals within and around organizational facilities using spectrum analyzers, Wi-Fi scanning tools, or site survey software. The survey detects unauthorized rogue access points, validates authorized AP configurations,…

    How to test + evidence

    Testing procedure: Coverage / interference / rogue survey at least quarterly.

    Evidence to collect: Most recent survey report.