Before approving the next municipal WLAN architecture review, security leadership wants a written allowlist of AKM suites (for example SAE and 802.1X-SHA256) that APs may advertise. Why does that policy artifact matter?
Select an answer to reveal the explanation.
Short Explanation
If it isn’t on the allowlist, it shouldn’t show up in the beacon. Writing down permitted AKMs—SAE, solid Enterprise suites, and friends—stops “temporary” weak suites from becoming permanent city policy by accident.
Full Explanation
Policy-driven allowlisting of AKM suites is part of WLAN security architecture governance: it states which authentication and key-management methods may be configured and advertised. It does not substitute for RSN information elements in beacons, mandate a universal PSK, or reduce to antenna purchasing paperwork. Written allowlists also give auditors a clear baseline when comparing live AP configurations to approved municipal standards.