WLAN SSIDs must be changed from the manufacturer's default to a pseudo random word that does not identify the unit, base, organization, etc.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-243227 | WLAN-NW-000200 | SV-243227r720136_rule | CCI-000366 | low |
| Description | ||||
| An SSID identifying the unit, site, or purpose of the WLAN or that is set to the manufacturer default may cause an OPSEC vulnerability. | ||||
| STIG | Date | |||
| Network WLAN Bridge Platform Security Technical Implementation Guide | 2023-02-13 | |||
Related Frameworks
4 paths across 3 frameworks
Related Frameworks
NIST 800-531 mapping
CM-6
1.00
- DISA · V7R2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.4.1
1.00
- DISA · V7R2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.4.2
1.00
- DISA · V7R2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000366
1.00
- DISA · V7R2 · disa_xccdf · related
Details
Check Text (C-243227r720136_chk)
Review device configuration.
1. Obtain the SSID using a wireless scanner or the AP or WLAN controller management software.
2. Verify the name is not meaningful (e.g., site name, product name, room number, etc.) and is not set to the manufacturer's default value.
If the SSID does not meet the requirement listed above, this is a finding.
Fix Text (F-46459r720135_fix)
Change the SSID to a pseudo random word that does not identify the unit, base, or organization.