9 hours 54 minutes
Hey, everyone, welcome back of the course. So in the last video we wrapped up our discussion on control 14 which is all about controlling access based on the actual need to know.
And this video where to talk through control 15 which is wireless access control.
So one of the main things that your average person has an issue with is a attached to public WiFi rights and the public WiFi is usually unsecured,
and also it's usually going to be sniffed by Attackers. So, for example, you're at the airport. You start just connecting to the airport WiFi for some reason,
and you're not using a VPN. And then he started entering in your banking password. You start surfing social media, etcetera, etcetera, and all this information is being harvested by that geeky guy next to you, right? Or that grandmother sitting across the way. So always make sure using a VPN as you're going through any type of public WiFi
at a minimum, and preferably
set up your own hot spots or use national service, you know. So a lot of cable cable providers, for example, will have, like a national ah national WiFi hot spots at least here in United States. And so you can connect with those and then also use a VPN is well,
so some control. 15 1
We're talking about maintaining an inventory of any types of authorized
wireless access points. So we want to make sure that we don't have any rogue devices on our network.
Some control 15 to basically detecting any type of weps that are connected to our wire network. Right? So that's the only way we can figure out something doesn't belong is if we can t detect the things that are on there. So we wanna make sure that as we're looking at our actual wired infrastructure,
where are these rogue devices? If there are any where these wireless access points
and we need to identify those and tracked them down a lot of times you may find that if you're new to accompany you come in. There could be a rogue access device sitting in a closet someplace the nobody's thought ever or seen in a long time. They didn't even think about it.
There could also just be innocuous or innocent
types of Weps sitting in a closet someplace that everyone forgot about for five years. So that's why it's important for us to detect all these things and understand what's actually on her network.
So control 15 3 using a wireless intrusion detection system.
So again, just going back to saying, Hey, this traffic doesn't belong. It doesn't look right. Well, let me tell somebody about it.
So control 15 4 Disabling wireless access on any device is if it's not actually required on. And that's just the Becks practice of
hardening those devices. So again, if there's not a legitimate business person purpose for it, disable it, block it, etcetera.
Limit the wireless access on client devices. So
if there's not an essential like business purse purpose for that that basically just allow access on Lee to authorize wireless networks and restrict access to any other wireless networks that they might be able to connect to
disabled appear to pure
wireless network capabilities on those wireless clients.
So basically, that's the ad hoc type of network capabilities.
Some control 15 7 leverage things like a s to encrypt wireless data. So that's just a sample view of the structure from them, our bites
and as technology of evolves, by the way and better encryption comes out.
Use that. So if you're watching this course 10 years from now, use the best encryption possible available to you.
Sub Control 15 8
Using the wireless authentication protocols that actually require multi factor authentication.
So, for example, like uh, E a p TLS so extensible authentication protocol transport layer security. Eso again
Just use things that are requiring that multi factor authentication
some control. 15 9 Disable any wireless personal access to devices. Eso, for example. Think of Bluetooth right or NFC near field Communications
unless there is a legitimate business purpose.
So again, if it's not needed blockade, disable it. If it is needed for some legitimate reason, figure out how long it's needed for who's gonna be responsible for it and document that stuff.
And finally, some control. 15 10. Create separatist wireless networks for personal and untrusted devices. So a lot of companies do this. They do the guest network, or they'll have a ah network for B Y O. D. As well as a guest network for people visiting the office.
So in this video, we just talked about CS Control 15 in the next video, where to see how the wireless access controls map up to the next cybersecurity framework