20.14 (L1) Ensure 'WLAN and WWAN is Disabled in BIOS'

Information

This policy setting ensures that wireless access (WLAN and WWAN) to the system is disabled at the basic input/output system (BIOS) level. In computing, BIOS is the firmware responsible for hardware initialization during the booting process, and also provides runtime services for operating systems (OS) and programs.

The recommended state for this setting is: Disabled

In a high security environment, wireless connections to secure workstations should be eliminated to reduce the attack surface of the system.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Ensure that wireless access (WLAN and WWAN) is disabled via the BIOS. Each System manufacturer will have a unique way of disabling the wireless capability.

Below are is an example of how to disable wireless in BIOS. For specific instructions on how to disable this feature, see the system manufacturer instructions.

-

Reboot

the system
-

Press

the F10 key at the power-on screen
-

After

the BIOS screen appears,

Navigate

to the Security Menu
-

Navigate

to the Security Menu
-

Navigate

to Device Security
-

Change

the Wireless Network Button to 'Disabled'

Note: This is just an example, the system manufacturer will determine how wireless is disabled.

Impact:

Wireless connections and access to the WLAN adapter in the user interface (UI) will be inaccessible.

See Also

https://workbench.cisecurity.org/benchmarks/17610

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: f21a7ebb5aa57d492fe38a26d3180e2aeb4fe01d66088d17ef87bc59a6b8b7c5