Mapped to NIST 800-171 Requirement: 3.1.15
CMMC Assessment Objective: AC.L2-3.1.15[b]
What This Objective Means
This objective focuses on governance—ensuring your policies and procedures mandate the use of encryption for all wireless access. This includes both internal systems and any third-party or vendor networks used to transmit CUI.
Your documentation must answer these questions:
• Is encryption required for all wireless connections?
• What encryption protocols are considered acceptable?
• Are there procedures for verifying encryption is configured properly?
Why It Matters
Encryption cannot be optional. If your policies don’t explicitly require it:
• Wireless data may be transmitted in plaintext
• Staff may configure access points without secure encryption
• CUI may be vulnerable to eavesdropping or interception
Clear policy language ensures encryption is not only expected—but required and auditable.
How to Implement It
• Update your Access Control Policy and procedures to:
◦ Require encryption (e.g., WPA2-Enterprise or WPA3 with AES)
◦ Reference FIPS 140-2 validated encryption when applicable
◦ Prohibit unsecured protocols like WEP or open networks
• Include language such as:
◦ “Wireless access to organizational systems must use encryption methods that meet or exceed FIPS 140-2 standards.”
• Ensure procedures include steps for:
◦ Validating encryption settings on WAPs
◦ Reviewing encryption during security audits
Evidence the Assessor Will Look For
• Access control policy and procedures with encryption requirements for wireless access
• Lists of approved encryption protocols
• Role-based responsibility assignments for managing wireless security
• Change logs showing recent policy updates, if applicable
Common Gaps
• No mention of encryption in access control policies
• Encryption required by practice but not by policy
• Procedures that rely on default WAP settings without review
How Cuick Trac Helps
Cuick Trac supports this control by:
• Providing policy templates that include encryption requirements for all wireless access
• Helping you align practices with written procedures through advisory support
• Enforcing encryption by default where wireless is supported or monitored
• Assisting with documentation for wireless encryption configurations
With Cuick Trac, encryption requirements are written clearly, implemented securely, and enforced consistently.
Final CTA
Wireless encryption shouldn’t be a guideline—it should be a requirement.
Schedule a Cuick Trac demo and embed strong encryption into every level of your policy stack.