NIST 800-171 Controls · Access Control
AC.2.017 — Protect Wireless Access Using Authentication and Encryption
Protect wireless access using authentication and encryption.
What AC.2.017 means in plain English
Your business Wi-Fi must use strong encryption (WPA2 or WPA3) with a strong password, so that the data traveling over the wireless signal is protected and random people nearby can't just join your network. WPA1 (old) and open/unsecured Wi-Fi are not acceptable. The password should be complex — not "shop1234" — and changed periodically.
The assessment question
“Is your business Wi-Fi network secured with WPA2 or WPA3 encryption and a strong, complex password (not a simple word or default router password), and have you verified that no access points are running older WEP or WPA1 encryption or are configured as open/unencrypted networks?”
How to implement AC.2.017
- Log into your router's admin page (usually 192.168.1.1 or 192.168.0.1) and navigate to Wireless Settings. Verify the security mode is set to WPA2-AES or WPA3. If it says WEP, WPA (version 1), or None/Open, change it immediately.
- Set a strong Wi-Fi password for your CUI network: minimum 16 characters, mixing uppercase, lowercase, numbers, and symbols. Use a password manager like Bitwarden to generate and store it.
- Enable WPA3 if your router and devices support it (most hardware manufactured after 2020 does). WPA3 is significantly more resistant to password-guessing attacks than WPA2.
- Conduct a wireless survey: walk around your facility and use a free tool like Wireless Network Watcher (NirSoft, free) to confirm no rogue or unauthorized access points are broadcasting near your facility.
- Change the Wi-Fi password on a schedule (every 6-12 months) and whenever an employee who knew the password leaves the company. Document the last date the password was changed.
Evidence your assessor will ask for
- Router admin console screenshot showing WPA2 or WPA3 encryption enabled on the CUI network
- Evidence that default router passwords have been changed (no specific password needed, just confirmation)
- Written policy specifying minimum Wi-Fi encryption standard (WPA2/WPA3) and password complexity requirements
- Wireless survey results confirming no unauthorized or unencrypted access points
Does AI prompt monitoring help with this control? Honestly, no.
AC.2.017 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Access Control controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.