SSIDs for wireless networks should be hidden for organizations located in high traffic, densely populated areas.

Control Type: Technical

Control Function: Preventive

Description: The Service Set Identifier (SSID) is what allows users to identify a wireless network. It is a basic setting that everybody with a Wireless Local Area Network (WLAN) has set up. There is inherent risk in exposing a WLAN's SSID. Being able to locate the network can pave an easy path for potential adversaries. Think about walking down Main Street in any town. There are likely dozens of offices and storefronts packed together. Opening a phone and checking the Available Networks is likely to reveal dozens of networks with their owner easily identifiable by SSID. You may even see a few Open Wi-Fi networks with no security!

A WLAN should only be usable by vetted employees. Everybody who needs to use the Wi-Fi should already be on it or know how to connect. Keeping a WLAN's SSID blasted out into public areas paints a target on an organization. Adversaries utilize a reconnaissance technique like Wardriving and Warflying to look for W-Fi networks to exploit. If an SSID clearly identifies an organization by name, adversaries can nail down the physical location and identify potential avenues for physical exploitation.

Organizations located in high traffic, densely populated areas should enable the Hide SSID option on SOHO routers or wireless access point controllers. This will stop broadcasting the network SSID, instead requiring users to enter the network name and credentials directly from their devices to access it. The WLAN signal will still be present, but it will take extra steps for adversaries to locate it and trace it directly to the organization.