11.2 Wireless access points are identified and monitored
How to meet it
Detect authorised and rogue wireless access points periodically.
Defined requirements
The individual PCI DSS v4.0.1 requirements under 11.2, in plain English.
11.2.1Authorized and unauthorized wireless access points are managed, detected at least every three months, with alerts where automated.
11.2.2An inventory of authorized wireless access points is kept with a business justification for each.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.Asset management policyUse for ISO 27001 A.5.9, A.5.10, A.5.11, A.7.9 to A.7.14, SOC 2 Security, and PCI DSS asset inventory expectations.Physical and environmental security policyUse for ISO 27001 A.7.1 to A.7.14, SOC 2 Security, and PCI DSS requirement 9 physical access controls.Human resources security policyUse for ISO 27001 A.6.1 to A.6.6, A.6.8, SOC 2 Security, and personnel security controls.
Open the control-to-policy map← 11.1 Processes and mechanisms are defined and understood11.3 Vulnerabilities are regularly identified, prioritised and addressed →
Back to Requirement 11, or see PCI DSS templates. To run PCI controls with automation, read how AI manages controls.