36 MAC Pt. 1, R. 4.3

Wireless Access

Year: 2026Length: 333 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 4.3

Wireless Access A. Each agency must ensure that all Wireless Local Area Networks (WLANS) are configured securely. 1. Authorize each type of wireless access prior to allowing such connections by establishing and maintaining a secure configuration process for network devices such as the access point and switches supporting the wireless access. 2. Protect wireless access using secure network management (TLS, SSH) and communication protocols (WPA2 and WPA3). 3. Utilize the Advanced Encryption Standard (AES) for wireless access. 4. Each agency must ensure that their wireless deployment encryption keys are rotated regularly and frequently (at least every 6 months). Further, all encryption keys should be changed if wireless access must be revoked (such as after termination or transfer of an employee). 5. ITS recommends disabling wireless access on devices that do not have a business purpose for wireless access. 6. ITS recommends disabling peer-to-peer wireless network capabilities on wireless clients. 7. ITS recommends configuring wireless access on client machines that do have an essential wireless business purpose, to allow access only to authorized wireless networks and to restrict access to other wireless networks. 8. ITS recommends ensuring that wireless networks use authentication protocols such as Extensible Authentication Protocol-Transport Layer Security (EAP/TLS) to provide credential protection and mutual authentication. 9. ITS recommends disabling wireless peripheral access of devices (such as Bluetooth), unless such access is required for a documented business need. B. Each agency must ensure that guest/public users are not permitted access to the state network resources. 1. Agencies wishing to provide Internet access to a guest user must utilize one of the following approved methods: i. Installing separate equipment and a separate circuit for guest users. Contact ITS for more information on this method of connectivity. ii. Tunneling guest user traffic to an ITS DMZ via a wireless controller solution implemented by ITS. Contact ITS for more information on this method of connectivity. 2. Both methods require: i. No ports opened inbound to guest users. ii. All guest user traffic must be filtered.
36 MAC Pt. 1, R. 4.3: Wireless Access | Justis AI