This standard specifies the technical requirements that wireless infrastructure devices must satisfy to connect to a CrowdFiber network. Only those wireless infrastructure devices that meet the requirements specified in this standard or are granted an exception by the InfoSec Team are approved for connectivity to a CrowdFiber network.

Network devices including, but not limited to, hubs, routers, switches, firewalls, remote access devices, modems, or wireless access points, must be installed, supported, and maintained by an Information Security (Infosec) approved support organization. Lab network devices must comply with the Lab Security Policy.

General Requirements

All wireless infrastructure devices that connect to a CrowdFiber network or provide access to CrowdFiber Confidential, CrowdFiber Highly Confidential, or CrowdFiber Restricted information must:

  • Use Extensible Authentication Protocol-Fast Authentication via Secure Tunneling (EAP-FAST), Protected Extensible Authentication Protocol (PEAP), or Extensible Authentication Protocol-Translation Layer Security (EAP-TLS) as the authentication protocol.
  • Use Temporal Key Integrity Protocol (TKIP) or Advanced Encryption System (AES) protocols with a minimum key length of 128 bits.
  • All Bluetooth devices must use Secure Simple Pairing with encryption enabled.

Lab and Isolated Wireless Device Requirements

  • Lab device Service Set Identifier (SSID) must be different from CrowdFiber production device SSID.
  • Broadcast of lab device SSID must be disabled.

Home Wireless Device Requirements

All home wireless infrastructure devices that provide direct access to a CrowdFiber network, such as those behind Enterprise Teleworker (ECT) or hardware VPN, must adhere to the following:

  • Enable WiFi Protected Access Pre-shared Key (WPA-PSK), EAP-FAST, PEAP, or EAP-TLS
  • When enabling WPA-PSK, configure a complex shared secret key (at least 20 characters) on the wireless client and the wireless access point
  • Disable broadcast of SSID
  • Change the default SSID name
  • Change the default login and password