Compliance Center
Policy Management and Reporting
AirMagnet provides its enterprise customers with the most accurate and useful tools for meeting industry regulation standards that relate to wireless networking. AirMagnet's Enterprise and WiFi Analyzer products are equipped with built-in policy-management and reporting tools for:
Basel II promotes greater consistency in the way banks and banking regulators approach risk management. It is designed to establish minimum levels of capital for internationally active banks and incorporates an explicit capital charge for operational risk, which includes the security risks in operating a wireless network.
AirMagnet technology and the Basel II Compliance Report support institutionally active banks' compliance with Basel II by identifying and mitigating the operational risks inherent in operating and maintaining wireless networks and devices
DoD Directive No. 8100.2 mandates security measures for the use of commercial wireless devices, services, and technologies in the DoD Global Information Grid.
AirMagnet technology and DoD 8100.2 Compliance Report helps DoD components meet the requirements of Directive 8100.2 by detecting rogue devices and denial of service attacks; monitoring wireless transmissions and devices for security penetration, user authentication, encryption schemes, and radio frequency interference; identifying device configuration, deployment, and control issues; and identifying wireless vulnerabilities and alerting appropriate personnel.
The EU-CRD, popularly known as CAD3 (Capital Adequacy Directive), implements the Basel II Accord in member countries and introduces new capital requirements for internationally active banks, credit institutions, and investment firms. Following Basel II, the EU CRD mandates the use of operational risk, including the risks in operating a wireless network, in calculating minimal levels of capital.
AirMagnet technology and the EU-CRD Compliance Report support banks, credit institutions, and investment firms to comply with the EU CRD by identifying and mitigating the operational risks inherent in operating and maintaining wireless networks and devices.
FISMA requires all U.S. agencies to develop, document, and implement an information security program for all their information systems and information assets, except those marked classified. It demands the use of key security controls for all access to information systems, configuration management schemes, and identification and authentication strategies.
AirMagnet technology and the FISMA Compliance Report monitors wireless traffic and devices and alerts agency personnel when key controls are not implemented or breached. In effect, AirMagnet helps agencies satisfy FISMA requirements that affect WLANs and ensures that wireless devices connecting to Federal agency information systems are secure.
GLBA requires financial institutions to develop and implement administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information. Regulations dictate the use of safeguards that control access to information, encrypt customer information, monitor systems, institute an incident response program, and test key controls on a regular basis.
AirMagnet technology and the GLBA Compliance Report help financial institutions implement GLBA-mandated safeguards for wireless networks and devices by: detecting threats; identifying deployment and control issues; monitoring wireless traffic and devices for security penetration and radio frequency interference; and alerting appropriate individuals of security incidents and advising them of appropriate steps to mitigate security events.
HIPAA aims to improve the efficiency and effectiveness of the nation's health care system and promote the use of electronic data interchange in health care. To accomplish these goals, the Department of Health and Human Services (HHS) established national standards for the security of electronic health care information and "protected health information" or PHI.
The HHS standards are, in effect, regulations that include administrative, physical, and technical safeguards for PHI. Each safeguard requires implementation specifications to maintain HIPAA compliance.
AirMagnet technology and the HIPAA Compliance Report incorporates HIPAA implementation specifications for wireless technology and devices. AirMagnet helps covered entities satisfy HHS regulations by, among other things, recording whether the entity has complied or is complying with the applicable administrative and physical safeguards for PHI (Protected Health Information); implementing policies and procedures to prevent, detect, contain, and correct security violations; and monitoring wireless traffic and devices for security and performance issues.
The ISO 27001 is a model to build an Information Management Security System (ISMS) as part and parcel for an organization's system that manages networks and systems. It is premised on identifying business risks and aims to establish a policy that includes objectives, processes, and procedures to manage the risks and thereby improve information security.
There are over 130 security objectives and controls in the ISO 27001. AirMagnet technology can satisfy ISO 27001 for wireless networks and devices by helping an organization plan security objectives and controls with the ISO 27001 Compliance Report. AirMagnet technology then monitors and checks the controls in real time and reports violations to the appropriate personnel. AirMagnet also supplies suggested approaches to mitigate identified risks and improve an ISMS.
When customers offer their payment card at a point of sale, over the Internet, on the telephone, or through the U.S. mail, they want assurance that their account information is safe. The PCI DSS offers a single approach for merchants who use payment cards for merchandise to safeguard sensitive data for all payment card brands, including Visa and MasterCard.
AirMagnet technology and the PCI DSS Compliance Report help address some of the basic requirements of the PCI DSS for wireless networks and devices. Among other things, AirMagnet insures that only authorized wireless devices access the network and makes sure that no vendor-supplied defaults linger on active devices. In addition, AirMagnet includes an intrusion detection system and regularly tests devices for known vulnerabilities. When systems are breached or vulnerabilities are identified, AirMagnet sends configurable alerts to administrations.
SOX aims to reform the accounting practices, financial disclosures, and corporate governance of public companies. Among other things, SOX requires public companies to attest to the integrity and control of their financial controls.
Since IT underlies the very business of financial recording and reporting, a lack of control over IT security implies a lack of control over the organization's financial reports. AirMagnet technology and the SOX Compliance Report offer public companies the ability to monitor and report on the wireless capability and security of devices that effect internal controls in financial reporting. AirMagnet monitors and reports on authentication, access controls, and encryption schemes for wireless networks and devices to show that network security policies areĀ implemented in a secure manner. It also provides an integral framework to guide network administrators to respond to security threats and incidents in a consistent, compliant, and approved manner.
Enterprise or WiFi Analyzer users can choose from a set of built-in policies for any one of these regulatory standards. Once policies are set, the system will automatically monitor the wireless LAN and generate alarms when it detects any events or devices that are out of compliance. Reports can then be generated to provide a step-by-step pass/fail assessment of every standard of the regulation, including a definition of the standard and a list of events or issues that caused non-compliance, if applicable. High-level dashboard views, such as pie charts, break down compliance into various categories to highlight vulnerabilities that require special attention. Using this end-to-end, policy-driven method to manage the wireless LAN is the only way to fully meet strict regulatory standards and the best way to maintain strict security.

See a sample report.
Did you know? AirMagnet Enterprise can feed alarms to your Security Information Manager (SIM) or Manager of Managers (MOM) system, such as ArcSight, Netcool, HP Openview, Guarded Net, etc. This enables policy-driven data to reach central managers, who often oversee compliance-related issues.
» Back to Top