Hello all. I'm writing an article about securing wireless in a HIPA enviroment. I have a few topics that I'm going to talk about, let me know if I need to add anything.
-Types of attacks, and why you should secure it in a Hipa enviroment.
-Roaming Security.
-Types of Encryption.
-Radius
-TLS
-Peap
-IPSec
-Ceritificates/Autentication.
Anything else I should add. I'm just brainstorming here. Thanks in advance.
I would add that in order to make a relevant case for WLAN security and HIPAA, you need to show how each security feature maps to HIPPA compliancy. Otherwise, you're just talking WLAN security.
How about Network Admission Control (NAC) posture assessment and profiling for WLAN clients/equipment? This is huge in Healthcare. Also, what about monitoring AP's specifically designed to track rogue attacks?
IPsec?? Not seeing how adding this overhead provides more security since it's primarily used now for site-2-site VPNs and remote-access VPNs. Dump this.
TLS, PEAP, and Certificates is really just authentication means for 802.1x WLAN deployment, which could simply be covered in a paragraph or two. More focus should be on 802.1x for AAA services than the means to authenticate.
I'm assuming you're going to be focusing on a Controller-based Architecture, right? If so, it would beneficial to talk about many of the security features with the Controller which also adds other Layer 2 and 3 security measures depending on Controller vendor.