PCI DSS Security Maturity Model·AWS v1.0.0
Foundational Security Assurance ☁ AWS

r11.2 Detection of unauthorized wireless access points

Detect and manage the presence of wireless access points (authorized and unauthorized). In a pure AWS environment there is no customer wireless infrastructure, which must be documented in scope.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: Low Applies to CDE: Yes

AWS services

AWS Config

Requirement 11

Test Security of Systems and Networks Regularly

PCI sub-requirements covered

  • 11.2 Wireless access points are identified and monitored, and unauthorized wireless access points are addressed

How to implement on AWS

For 100% AWS deployments, document that no wireless networks exist within the customer scope. In hybrid environments, maintain an inventory of authorized access points and processes for detecting unauthorized ones; centralize the evidence and its periodic review.

Practical implementation

How this control is implemented in each reference architecture:

In a pure AWS single account there is no customer wireless; document non-applicability. If hybrid wireless exists, keep the authorized-AP inventory and quarterly detection records.

Single-account, 3-tier →

Document wireless non-applicability once at the org level; for hybrid environments, manage detection from the central network account and record it against the shared responsibility matrix.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineinterview

Testing procedures

  • Examine the methodology and documentation and interview personnel to verify processes detect and identify both authorized and unauthorized wireless access points at least every 3 months (11.2.1.b, 11.2.1.c).
  • Examine documentation to verify an inventory of authorized wireless access points with business justification is maintained (11.2.2). On AWS this is typically AWS-managed; document non-applicability for the customer scope where applicable.

Evidence in AWS

  • PCI scope document indicating applicability or non-applicability of wireless.
  • Where applicable: inventory of authorized APs and quarterly detection records.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 11.2 — Unauthorized wireless access points are identified and addressed periodically.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 11.2