r11.2 Detection of unauthorized wireless access points
Detect and manage the presence of wireless access points (authorized and unauthorized). In a pure AWS environment there is no customer wireless infrastructure, which must be documented in scope.
AWS services
Requirement 11
Test Security of Systems and Networks Regularly
PCI sub-requirements covered
- 11.2 Wireless access points are identified and monitored, and unauthorized wireless access points are addressed
How to implement on AWS
For 100% AWS deployments, document that no wireless networks exist within the customer scope. In hybrid environments, maintain an inventory of authorized access points and processes for detecting unauthorized ones; centralize the evidence and its periodic review.
Practical implementation
How this control is implemented in each reference architecture:
In a pure AWS single account there is no customer wireless; document non-applicability. If hybrid wireless exists, keep the authorized-AP inventory and quarterly detection records.
Single-account, 3-tier →Document wireless non-applicability once at the org level; for hybrid environments, manage detection from the central network account and record it against the shared responsibility matrix.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine the methodology and documentation and interview personnel to verify processes detect and identify both authorized and unauthorized wireless access points at least every 3 months (11.2.1.b, 11.2.1.c).
- Examine documentation to verify an inventory of authorized wireless access points with business justification is maintained (11.2.2). On AWS this is typically AWS-managed; document non-applicability for the customer scope where applicable.
Evidence in AWS
- PCI scope document indicating applicability or non-applicability of wireless.
- Where applicable: inventory of authorized APs and quarterly detection records.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 11.2 — Unauthorized wireless access points are identified and addressed periodically.
Learning resources
References
- PCI DSS v4.0.1 Requirement 11.2
PCI DSS Security Maturity Model