AC.L2-3.1.15[b]: Require Encryption for Wireless Access in Policy and Procedure

Mapped to NIST 800-171 Requirement: 3.1.15
CMMC Assessment Objective: AC.L2-3.1.15[b]

What This Objective Means
This objective focuses on governance—ensuring your policies and procedures mandate the use of encryption for all wireless access. This includes both internal systems and any third-party or vendor networks used to transmit CUI.
Your documentation must answer these questions:
• Is encryption required for all wireless connections?
• What encryption protocols are considered acceptable?
• Are there procedures for verifying encryption is configured properly?

Why It Matters
Encryption cannot be optional. If your policies don’t explicitly require it:
• Wireless data may be transmitted in plaintext
• Staff may configure access points without secure encryption
• CUI may be vulnerable to eavesdropping or interception
Clear policy language ensures encryption is not only expected—but required and auditable.

How to Implement It
• Update your Access Control Policy and procedures to:
◦ Require encryption (e.g., WPA2-Enterprise or WPA3 with AES)
◦ Reference FIPS 140-2 validated encryption when applicable
◦ Prohibit unsecured protocols like WEP or open networks
• Include language such as:
◦ “Wireless access to organizational systems must use encryption methods that meet or exceed FIPS 140-2 standards.”
• Ensure procedures include steps for:
◦ Validating encryption settings on WAPs
◦ Reviewing encryption during security audits

Evidence the Assessor Will Look For
• Access control policy and procedures with encryption requirements for wireless access
• Lists of approved encryption protocols
• Role-based responsibility assignments for managing wireless security
• Change logs showing recent policy updates, if applicable

Common Gaps
• No mention of encryption in access control policies
• Encryption required by practice but not by policy
• Procedures that rely on default WAP settings without review

How Cuick Trac Helps
Cuick Trac supports this control by:
• Providing policy templates that include encryption requirements for all wireless access
• Helping you align practices with written procedures through advisory support
• Enforcing encryption by default where wireless is supported or monitored
• Assisting with documentation for wireless encryption configurations
With Cuick Trac, encryption requirements are written clearly, implemented securely, and enforced consistently.

Final CTA
Wireless encryption shouldn’t be a guideline—it should be a requirement.
Schedule a Cuick Trac demo and embed strong encryption into every level of your policy stack.

🍪 We Use Cookies

To enhance your experience and analyze site usage, we use cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.