A city payments kiosk SSID may process cardholder data and sits near HIPAA-adjacent clinic check-in devices. What should security policy authors do first?
Select an answer to reveal the explanation.
Short Explanation
Regulations don’t care that it’s “just Wi-Fi.” Translate PCI and clinic-adjacent rules into plain WLAN policy: who can join, how it’s encrypted, how it’s segmented. A café template and a privacy banner won’t satisfy auditors—or residents.
Full Explanation
WLAN security policy must translate regulatory obligations (e.g., PCI-DSS for payment paths and HIPAA-adjacent handling near clinical workflows) into enforceable controls: authentication, encryption, segmentation, logging, and ownership. Treating wireless as exempt because wired controls exist leaves the RF path unmanaged. Consumer templates and cosmetic portal banners do not constitute mapped policy.