US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.16
Wireless Access Monitoring
(Rev. 15)
As outlined in the MAC ARS, wireless access to a MAC network is not allowed unless explicitly
approved in accordance with AC-18. MAC ARS AC-18 also states that an organization must
monitor for unauthorized wireless access. Business partners must have a program in place to fulfill
this requirement and have associated policies and procedures outlining how the program is
operated. The implementation must be capable of identifying unauthorized wireless devices or
access points that could be providing access to the network. Monitoring activities should be
performed on a periodic basis as needed, but at least quarterly to confirm that unauthorized wireless
access does not exist and/or is removed. If wireless access to the environment has been
appropriately approved, an accurate and formally maintained listing of approved access points must
be maintained to perform effective monitoring. The approved wireless access point list should be
reviewed during the monitoring process to capture necessary updates.
History
(Rev. 15)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
f0d33ff315f3fe004c41dec72347c09574841a77ac1045e29f3eed4e45b71933
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.