PCI DSS 11.2.2: An inventory of authorized wireless access points is maintained

PCI DSS v4.0.1 control 11.2.2: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 11.2.

Requirement 11: Test Security of Systems and Networks Regularly › Section 11.2

An inventory of authorized wireless access points is maintained, including a documented business justification.

Summary

Keep a list of the wireless access points you authorised, and a written reason for each one.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
11.2.2 Examine documentation to verify that an inventory of authorized wireless access points is maintained, and a business justification is documented for all authorized wireless access points.

The other half of 11.2.1: you cannot identify an access point as unauthorised without a list of the authorised ones, so an entity doing quarterly detection against no inventory is producing findings it cannot classify. The element entities skip is the documented business justification, and it is per access point rather than per network. That granularity is deliberate, because the access point nobody can justify is usually the one installed for a project that ended, and the justification is what surfaces it. Note that this inventory serves 1.3.3 and 4.2.1.2 as well, both of which need to know which wireless networks exist.

What to prepare

  • The inventory: each access point, its location, the network it serves, and its owner.
  • A business justification per access point.
  • How the inventory is kept current when one is added or removed.

How to implement it

1. Justify each one, not each network. A justification for "corporate Wi-Fi" leaves every individual access point unaccounted for, which is the level the control asks about.

2. Include the ones you did not install. Access points that arrived with a fit-out, a vendor, or a managed print service are yours for this purpose once they are on your premises.

3. Retire what cannot be justified. The usual first pass over an inventory removes more than it documents, and every removal is one less thing to survey and defend.

4. Make it the reference for the quarterly detection. One list serving both controls stays current because it is used.

Where this commonly fails

  • An inventory with no justifications, satisfying half the control.
  • Justification recorded at network level, so individual access points are invisible.
  • Access points installed by a third party never entered.
  • The list maintained by the network team while facilities install more, so the two never agree.

Others in section 11.2:

Control What it requires
11.2.1 Authorized and unauthorized wireless access points…

11.2.1 · All controls · 11.3.1

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.