1.7 Do not connect to untrusted Wi-Fi networks

Information

The Do not connect to untrusted Wi-Fi networks setting protects users from potential security threats when connecting to Wi-Fi networks. When this setting is enabled, the device will automatically avoid connecting to any Wi-Fi networks that it deems untrusted, based on a set of predefined criteria.

The recommended state for this setting is: Only connect to trusted networks.

Rationale:

Connecting a device to an open untrusted network through unsecured channels can increase the remote attack surface of the device. The cellular data network is a more difficult medium to inspect compared to Wi-Fi. If a user is going to be using public Wi-Fi, using a secure VPN is recommended. In most cases, you should avoid using a public, untrusted or free Wi-Fi.

Impact:

A user might have to use cellular data and would not be able to take advantage of public Wi-Fi networks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow the below steps to disable Wi-Fi or connect to a trusted network:

Open phone's Settings app.

Tap Network & internet.

Toggle Wi-Fi setting to the Off position or connect to a trusted network.

See Also

https://workbench.cisecurity.org/benchmarks/23192

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-18

Plugin: MDM

Control ID: 24817e71de7d94152b121839baa03d7be20e8735f8a37a21b443145f1c0e575e