id: "SC-40" title: "Wireless Link Protection" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-40" priority: "P1" implementation_level: "system" enhancements: - sc-40.1 - sc-40.2 - sc-40.3 - sc-40.4


Statement

Protect external and internal {{ insert: param, sc-40_prm_1 }} from the following signal parameter attacks: {{ insert: param, sc-40_prm_2 }}.

Guidance

Wireless link protection applies to internal and external wireless communication links that may be visible to individuals who are not authorized system users. Adversaries can exploit the signal parameters of wireless links if such links are not adequately protected. There are many ways to exploit the signal parameters of wireless links to gain intelligence, deny service, or spoof system users. Protection of wireless links reduces the impact of attacks that are unique to wireless systems. If organizations rely on commercial service providers for transmission services as commodity items rather than as fully dedicated services, it may not be possible to implement wireless link protections to the extent necessary to meet organizational security requirements.

Assessment Objective: external {{ insert: param, sc-40_odp.01 }} are protected from {{ insert: param, sc-40_odp.02 }}.

Assessment Objective: internal {{ insert: param, sc-40_odp.03 }} are protected from {{ insert: param, sc-40_odp.04 }}.

System and communications protection policy

access control policy and procedures

procedures addressing wireless link protection

system design documentation

wireless network diagrams

system configuration settings and associated documentation

system architecture

list of internal and external wireless links

list of signal parameter attacks or references to sources for attacks

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel authorizing, installing, configuring, and/or maintaining internal and external wireless links

Mechanisms supporting and/or implementing the protection of wireless links