S 6.102 Procedures in the event of WLAN security incidents

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator, User

If the WLAN does not respond as intended (e.g. the WLAN is unavailable for a long period of time, access to network resources is impossible, or the network performance is reduced for a long period of time), this may be caused by a security incident. This can be brought about by an attacker, faulty configurations, or system errors.

In this case, users should take the following items into consideration:

The administrators should initiate appropriate countermeasures when a security incident occurs. Examples of possible actions include:

If access points have been stolen, specific security safeguards must be taken, for example:

The possible consequences of events critical to security must be examined. Finally, all safeguards necessary to make it impossible to use stolen devices to gain access to the network of the organisation must be implemented. If a WLAN client is stolen, the client certificates must also be blocked if a certificate-based authentication method is used.

Review questions: