A regional transit agency asks for "strong Wi-Fi security" but has not written business goals for ops tablets versus public rider Wi-Fi. What should the security professional do first when forming WLAN security requirements?
Select an answer to reveal the explanation.
Short Explanation
"Strong security" is a vibe, not a requirement. Nail what the ops tablets need and how guest Wi-Fi must stay split—then pick gear. Shopping for toys first is how you get expensive misalignment.
Full Explanation
WLAN security requirements should flow from documented business and technical objectives—availability for operational clients, isolation of public access, regulatory constraints, and similar goals. Selecting products or copying another agency's SSIDs before those objectives are translated into measurable requirements produces poorly fitted controls. RF planning alone also does not substitute for security requirements definition.