Control statement
- a.Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and
- b.Authorize each type of wireless access to the system prior to allowing such connections.
Discussion
Wireless technologies include microwave, packet radio (ultra-high frequency or very high frequency), 802.11x, and Bluetooth. Wireless networks use authentication protocols that provide authenticator protection and mutual authentication.
From control text to operational evidence
Use Wireless Access as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to identity, authorization, least privilege, session boundaries, and access lifecycle governance.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- access approvals and entitlement records
- role and group configuration exports
- periodic access review results
- authentication and authorization logs
Common failure patterns
- standing privileges that outlive business need
- shared or orphaned accounts
- access rules implemented differently across systems
- approvals that cannot be traced to actual permissions
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- AC-18a.
- AC-18a.[01]configuration requirements are established for each type of wireless access;
- AC-18a.[02]connection requirements are established for each type of wireless access;
- AC-18a.[03]implementation guidance is established for each type of wireless access;
- AC-18b.each type of wireless access to the system is authorized prior to allowing such connections.
Examine
- Access control policy
- procedures addressing wireless access implementation and usage (including restrictions)
- configuration management plan
- system design documentation
- system configuration settings and associated documentation
- wireless access authorizations
- system audit records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with responsibilities for managing wireless access connections
- organizational personnel with information security responsibilities
Test
- Wireless access management capability for the system
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
AC-18(1) — Authentication and Encryption
Protect wireless access to the system using authentication of [Organization-defined: ac-18.01_odp] and encryption.
Official discussion
Wireless networking capabilities represent a significant potential vulnerability that can be exploited by adversaries. To protect systems with wireless access points, strong authentication of users and devices along with strong encryption can reduce susceptibility to threats by adversaries involving wireless technologies.
Organization-defined parameters (1)
Assessment objectives and methods
- AC-18(01)[01]wireless access to the system is protected using authentication of [Organization-defined: ac-18.01_odp];
- AC-18(01)[02]wireless access to the system is protected using encryption.
Examine
- Access control policy
- procedures addressing wireless implementation and usage (including restrictions)
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developers
Test
- Mechanisms implementing wireless access protections to the system
Related controls
AC-18(2) — Monitoring Unauthorized Connections
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
AC-18(3) — Disable Wireless Networking
Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.
Official discussion
Wireless networking capabilities that are embedded within system components represent a significant potential vulnerability that can be exploited by adversaries. Disabling wireless capabilities when not needed for essential organizational missions or functions can reduce susceptibility to threats by adversaries involving wireless technologies.
Assessment objectives and methods
when not intended for use, wireless networking capabilities embedded within system components are disabled prior to issuance and deployment.
Examine
- Access control policy
- procedures addressing wireless implementation and usage (including restrictions)
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
Test
- Mechanisms managing the disabling of wireless networking capabilities internally embedded within system components
AC-18(4) — Restrict Configurations by Users
Identify and explicitly authorize users allowed to independently configure wireless networking capabilities.
Official discussion
Organizational authorizations to allow selected users to configure wireless networking capabilities are enforced, in part, by the access enforcement mechanisms employed within organizational systems.
Assessment objectives and methods
- AC-18(04)[01]users allowed to independently configure wireless networking capabilities are identified;
- AC-18(04)[02]users allowed to independently configure wireless networking capabilities are explicitly authorized.
Examine
- Access control policy
- procedures addressing wireless implementation and usage (including restrictions)
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
Test
- Mechanisms authorizing independent user configuration of wireless networking capabilities
Related controls
AC-18(5) — Antennas and Transmission Power Levels
Select radio antennas and calibrate transmission power levels to reduce the probability that signals from wireless access points can be received outside of organization-controlled boundaries.
Official discussion
Actions that may be taken to limit unauthorized use of wireless communications outside of organization-controlled boundaries include reducing the power of wireless transmissions so that the transmissions are less likely to emit a signal that can be captured outside of the physical perimeters of the organization, employing measures such as emissions security to control wireless emanations, and using directional or beamforming antennas that reduce the likelihood that unintended receivers will be able to intercept signals. Prior to taking such mitigating actions, organizations can conduct periodic wireless surveys to understand the radio frequency profile of organizational systems as well as other systems that may be operating in the area.
Assessment objectives and methods
- AC-18(05)[01]radio antennas are selected to reduce the probability that signals from wireless access points can be received outside of organization-controlled boundaries;
- AC-18(05)[02]transmission power levels are calibrated to reduce the probability that signals from wireless access points can be received outside of organization-controlled boundaries.
Examine
- Access control policy
- procedures addressing wireless implementation and usage (including restrictions)
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
Test
- Calibration of transmission power levels for wireless access
- radio antenna signals for wireless access
- wireless access reception outside of organization-controlled boundaries
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.