GRP1 Task 2: WGU C844 WLAN and Mobile Security Plan
A. WLAN Vulnerabilities
1. Lack of Network Segmentation
○ Description: The current WLAN infrastructure does not segment traffic
between employee devices, BYOD devices, and potential guest networks. The
shared
office space and BYOD policy exacerbate this risk by allowing unsecured devices
onto the same network.
○ Risk: A compromised device on the network could have unrestricted access to
sensitive corporate resources, increasing the risk of data breaches or malware
propagation. For example, an employee’s personal device infected with malware
could spread to company-owned devices.
2. Insufficient Access Point Security
○ Description: Wireless access points (WAPs) may not utilize WPA3 encryption
or enterprise-grade security protocols. The reliance on a basic setup in an old
warehouse building likely means these access points lack modern security
features.
○ Risk: The use of older encryption standards, such as WPA2, makes the network
susceptible to brute force and key reinstallation attacks (e.g., KRACK).
Unauthorized access could compromise data integrity and confidentiality,
especially given the absence of a dedicated network security team.
B. Mobile Vulnerabilities
1. Insecure BYOD Devices
○ Description: Employees’ personal devices may lack adequate security controls
such as antivirus software, device encryption, and regular updates. Account
representatives using personal devices while traveling are particularly at risk.
○ Risk: Malware or other security threats on personal devices can infiltrate the
company’s network and compromise sensitive information. For example, a
compromised personal tablet connecting to the network could allow unauthorized
access to proprietary data.
2. Unsecured Communication Channels
®™ GRP1 Task 2: WGU C844 WLAN and Mobile Security Plan
A. WLAN Vulnerabilities
1. Lack of Network Segmentation
○ Description: The current WLAN infrastructure does not segment traffic
between employee devices, BYOD devices, and potential guest networks. The
shared
office space and BYOD policy exacerbate this risk by allowing unsecured devices
onto the same network.
○ Risk: A compromised device on the network could have unrestricted access to
sensitive corporate resources, increasing the risk of data breaches or malware
propagation. For example, an employee’s personal device infected with malware
could spread to company-owned devices.
2. Insufficient Access Point Security
○ Description: Wireless access points (WAPs) may not utilize WPA3 encryption
or enterprise-grade security protocols. The reliance on a basic setup in an old
warehouse building likely means these access points lack modern security
features.
○ Risk: The use of older encryption standards, such as WPA2, makes the network
susceptible to brute force and key reinstallation attacks (e.g., KRACK).
Unauthorized access could compromise data integrity and confidentiality,
especially given the absence of a dedicated network security team.
B. Mobile Vulnerabilities
1. Insecure BYOD Devices
○ Description: Employees’ personal devices may lack adequate security controls
such as antivirus software, device encryption, and regular updates. Account
representatives using personal devices while traveling are particularly at risk.
○ Risk: Malware or other security threats on personal devices can infiltrate the
company’s network and compromise sensitive information. For example, a
compromised personal tablet connecting to the network could allow unauthorized
access to proprietary data.
2. Unsecured Communication Channels
®™ GRP1 Task 2: WGU C844 WLAN and Mobile Security Plan