Wireless Communication Standard

OVERVIEW

This standard specifies the technical requirements that wireless infrastructure devices must satisfy to connect to a 10ARK DIGITAL network. Only those wireless infrastructure devices that meet the requirements specified in this standard or are granted an exception by the InfoSec team are approved for connectivity to a 10ARK DIGITAL network.

Network devices including, but not limited to, hubs, routers, switches, firewalls, remote access devices, modems, or wireless access points, must be installed, supported, and maintained by an Information Security (Infosec) approved support organisation.

SCOPE

All employees, contractors, consultants, temporary and other workers at 10ARK DIGITAL and its subsidiaries, including all personnel that maintain a wireless infrastructure device on behalf of 10ARK DIGITAL, must comply with this standard. This standard applies to wireless devices that make a connection to the network and all wireless infrastructure devices that provide wireless connectivity to the network.

Infosec must approve exceptions to this standard in advance.

STANDARD

General Requirements

All wireless infrastructure devices that connect to a 10ARK DIGITAL network or provide access to 10ARK DIGITAL Confidential, 10ARK DIGITAL Highly Confidential or 10ARK DIGITAL Restricted information must:

  • Use Extensible Authentication Protocol-Fast Authentication via Secure Tunnelling (EAP-FAST), Protected Extensible Authentication Protocol (PEAP), or Extensible Authentication Protocol-Translation Layer Security (EAP-TLS) as the authentication protocol

  • Use Temporal Key Integrity Protocol (TKIP) or Advanced Encryption System (AES) protocols with a minimum key length of 128 bits

  • All Bluetooth devices must use Secure Simple Pairing with encryption enabled

Lab and Isolated Wireless Device Requirements

  • Lab device Service Set Identifier (SSID) must be different from 10ARK DIGITAL production device SSID

  • Broadcast of lab device SSID must be disabled

Home Wireless Device Requirements

All home wireless infrastructure devices that provide direct access to a 10ARK DIGITAL network, such as those behind Enterprise Teleworker (ECT) or hardware VPN, must adhere to the following:

  • Enable WiFi Protected Access Pre-shared Key (WPA-PSK), EAP-FAST, PEAP or EAP-TLS

  • When enabling WPA-PSK, configure a complex shared secret key (at least 20 characters) on the wireless client and the wireless access point

  • Disable broadcast of SSID

  • Change the default SSID name

  • Change the default login and password

POLICY COMPLIANCE

Compliance Measurement

The Infosec team will verify compliance to this policy through various methods, including but not limited to, periodic walk-thrus, video monitoring, business tool reports, internal and external audits, and feedback to the policy owner.

Exceptions

Any exception to the policy must be approved by the Infosec Team in advance.

Non-Compliance

An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.

Last updated

Was this helpful?