12.07.2015 Views

INTERNATIONAL ISO/IEC STANDARD 18028-1

INTERNATIONAL ISO/IEC STANDARD 18028-1

INTERNATIONAL ISO/IEC STANDARD 18028-1

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>ISO</strong>/<strong>IEC</strong> <strong>18028</strong>-1:2006(E)— flawed SNMP used to manage WLANs,— not always possible to see who is using a WLAN.13.2.4.3 ControlsThe controls needed for WLANs include:— firewalling the WLAN from the corporate infrastructure,— implementing an IPsec based VPN over the WLAN between the client and a perimeter firewall,— giving consideration to improving the security of each WLAN device, by configuring personal firewalls andintrusion detection and anti-virus software on the client device,— control of transmission levels to eliminate a spread outside an organization's physical domain,— SNMP configured for read only access,— Out of Band encrypted management, for example using SSH,— maintaining physical security to wireless access points,— hardening of any server components,— system testing,— giving consideration to deploying an IDS between the corporate network and the wireless network.13.2.5 Radio Networks13.2.5.1 BackgroundRadio Networks are specified as networks using radio waves as a connection medium to cover geographicallywide areas. Typical examples of radio networks are mobile phone networks using technologies such as GSMor UMTS and providing public available voice and data services.It is emphasized that networks using radio waves to cover small areas are considered as a different categoryand are referred to in Clause 13.2.4.Examples of radio networks include:— TETRA— GSM— 3G (including UMTS),— GPRS,— CDPD,— CDMA.13.2.5.2 Security RisksThere are a number of general security threat scenarios which can result in risks applicable to radio networks,including:— eavesdropping,— session hijacking,— impersonation,— application level threats, e.g. fraud,— denial of service.© <strong>ISO</strong>/<strong>IEC</strong> 2006 - All rights reserved 33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!