id: "SI-04(14)" title: "Wireless Intrusion Detection" family: "SI" family_name: "System and Information Integrity" sort_id: "si-04.14" priority: "P1" implementation_level: "system" parent: "SI-04" enhancement: True


Statement

Employ a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to the system.

Guidance

Wireless signals may radiate beyond organizational facilities. Organizations proactively search for unauthorized wireless connections, including the conduct of thorough scans for unauthorized wireless access points. Wireless scans are not limited to those areas within facilities containing systems but also include areas outside of facilities to verify that unauthorized wireless access points are not connected to organizational systems.

Assessment Objective: a wireless intrusion detection system is employed to identify rogue wireless devices;

Assessment Objective: a wireless intrusion detection system is employed to detect attack attempts on the system;

Assessment Objective: a wireless intrusion detection system is employed to detect potential compromises or breaches to the system.

System and information integrity policy

system and information integrity procedures

procedures addressing system monitoring tools and techniques

system design documentation

system monitoring tools and techniques documentation

system configuration settings and associated documentation

system protocols

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for monitoring the system

organizational personnel responsible for the intrusion detection system

Organizational processes for intrusion detection

mechanisms supporting and/or implementing a wireless intrusion detection capability