4.2 Network Components & Endpoint Security
4.2 Network Components & Endpoint Security
Secure networks depend not only on architecture, but also on the infrastructure, transmission media and endpoints that actually implement that architecture.
For CISSP, this means understanding how network infrastructure should be operated and supported, how physical and wireless transmission media can introduce risk, how Network Access Control decides which devices may connect, and how host-based controls protect endpoints after connection.
Infrastructure
Secure, maintain and support the devices that carry network traffic.
NETWORK COMPONENTSTransmission
Protect copper, fibre and wireless communication paths.
MEDIAEndpoint
Decide whether devices may connect and protect the hosts themselves.
NAC + HOST SECURITYThe Big Idea
A secure network architecture can still fail if the components implementing it are poorly managed.
4.2 Memory Aid
Operate ยท Protect ยท Admit ยท Defend
Four Areas to Remember
Secure operation, redundancy, power, warranty, support and lifecycle.
Physical protection and quality of the communication signal.
Determine whether physical and virtual devices should receive network access.
Apply host-based security controls to connected devices.
The Official 4.2 Structure
๐ Network Infrastructure Components The devices that implement the network architecture
Network infrastructure contains many specialised components.
Connects devices within network environments and forwards traffic between interfaces according to switching logic.
Connects different IP networks and determines where packets should be forwarded.
Controls network traffic according to defined security policy.
Connects wireless clients to network infrastructure.
Distributes service traffic across multiple available resources.
Intermediates communication between clients and other services.
Terminates protected network communication from remote users or other networks.
Provides centralised management or control functions in modern software-defined environments.
Routers, switches, firewalls and controllers run software, have administrative interfaces, contain credentials and require security maintenance just like other information systems.
๐ง Secure Operation of Infrastructure Network devices require lifecycle security too
Configure network devices according to approved security standards.
Security vulnerabilities in network-device software must be assessed and remediated appropriately.
Administrative access should require appropriate authentication, authorisation and accountability.
Prefer protected administrative mechanisms rather than exposing credentials and commands unnecessarily.
Important device configurations should be recoverable after failure or replacement.
Administrative and security-relevant events should be available for monitoring and investigation.
Disable unnecessary services, interfaces and management methods.
Access to infrastructure hardware, console ports and cabling should be appropriately restricted.
A firewall is correctly filtering production traffic.
However, its administrative interface is accessible from every user workstation using a shared administrator password.
The network policy may be correct while the firewall itself is poorly secured.
Infrastructure Hardening
๐ ๏ธ Protect the Management Plane Administrative access can control the whole network
Network infrastructure often provides powerful administrative interfaces.
An attacker who compromises those interfaces may be able to:
Management-Plane Protections
Separate administrative access from ordinary user traffic where appropriate.
Only authorised administrative systems should reach management interfaces.
Stronger authentication reduces reliance on a single credential.
Administrative actions should be attributable to specific people.
Protect administrative sessions against interception.
Privileged changes should generate appropriate logs and alerts.
๐ Infrastructure Redundancy Design so one component failure does not remove the service
Network infrastructure often supports business-critical communication.
Availability architecture may therefore include redundancy at several levels.
A device can continue operating if one internal power supply fails.
Power supplies should not unnecessarily depend on the same single electrical source.
Alternate network paths can maintain communication after a link failure.
Multiple routers, firewalls or switches can reduce dependency on one hardware component.
Components may operate as coordinated pairs or clusters.
Critical network services may need alternate locations as well as alternate local devices.
A router has two power supplies.
Both are connected to:
the same power strip.
The router has redundant power supplies but still depends on one upstream electrical component.
Duplicate components provide limited resilience if they eventually converge on the same power source, cable route, provider or management dependency.
๐ Failover Redundancy must actually become usable during failure
Failover mechanisms should be maintained and tested.
Two firewalls exist in a high-availability pair.
Nobody has tested failover for three years.
When the primary fails, the secondary contains an outdated configuration and cannot handle production traffic.
๐ ๏ธ Warranty, Support & Lifecycle Infrastructure must remain maintainable
Hardware availability depends on more than whether the device is functioning today.
Can security fixes, technical assistance and replacement services still be obtained?
Is failed equipment covered by an appropriate replacement arrangement?
Can critical hardware be replaced quickly enough?
Does the vendor still provide security and maintenance support?
Can the infrastructure continue supporting required protocols and security capabilities?
Is migration planned before support becomes a crisis?
A core switch still works perfectly.
The vendor no longer provides:
The device has become a lifecycle and resilience risk even though it has not yet failed.
Infrastructure Lifecycle
Working โ Supported โ Resilient
The Signal Needs Protection Too
Network communication ultimately travels through a physical medium.
Security therefore depends partly on:
๐ Copper, Fibre & Wireless Different transmission technologies introduce different risks
| Medium | Signal | Important Security Considerations |
|---|---|---|
| Copper | Electrical | Physical tapping, electromagnetic interference, signal attenuation, crosstalk and cable-route protection. |
| Fibre | Light | Physical tapping remains possible, but fibre is resistant to electromagnetic interference and is useful across longer distances. |
| Wireless | Radio / electromagnetic transmission | Signal propagation beyond physical boundaries, interference, jamming and eavesdropping risk. |
Transmission Media
๐งต Copper Cabling Electrical signals are affected by the surrounding environment
Security & Reliability Considerations
Physical access to cabling can create opportunities to intercept or manipulate communication.
External electromagnetic energy can interfere with electrical signalling.
Radio-frequency sources may disrupt signal quality.
Signals in one conductor can interfere with neighbouring conductors.
Signal strength reduces as communication travels through the medium.
Cables can be cut, crushed, disconnected or otherwise damaged.
A network cable is routed beside high-power electrical machinery.
Interference creates repeated communication errors.
This is a signal-quality and availability problem, not necessarily a routing problem.
๐ก Fibre-Optic Cabling Transmit information using light rather than electrical signals
Advantages
Security Considerations
Fibre should still be protected against unauthorised access and physical tapping.
Fibres can still be cut or physically damaged.
Excessive bending can degrade signal transmission.
Multiple fibre connections offer limited resilience if they share the same physical duct.
Fibre can reduce some forms of signal leakage and interference, but physical access to the medium still matters.
๐ก Wireless Transmission The signal is not confined to a cable
Wireless signals propagate through the surrounding environment rather than remaining inside a physical cable.
Risks
An attacker within radio range may receive transmitted signals.
Other transmitters or environmental conditions may degrade communication.
Deliberate interference may affect availability.
Signals may extend beyond the intended physical area.
Unauthorised wireless devices can create additional communication paths.
A secure access point cannot compensate for every weakness on the connecting endpoint.
Wireless security therefore requires appropriate authentication, encryption, segmentation and monitoring.
๐ถ Signal Propagation Quality Availability depends on reliable transmission
Signal strength reduces as distance or transmission conditions affect the signal.
Other signals or electromagnetic sources degrade communication.
Unwanted signal energy can reduce communication quality.
Compares the desired signal with unwanted noise.
Physical structures may affect wireless propagation.
Transmission technologies have practical distance limitations.
Signal Quality
๐ก๏ธ Physical Security of Network Media Protect the path, not only the devices at each end
An organisation buys two fibre connections from two different telecommunications providers.
Both enter the building through:
the same underground duct.
A single construction accident could sever both links.
Media Resilience
Should This Device Be Allowed to Connect?
Network Access Control - NAC - applies policy when users or devices attempt to access network resources.
NAC
๐ฉบ Device Posture Assessment Identity may not be enough
NAC can consider the security state of a connecting endpoint as part of the access decision.
Possible Posture Checks
An employee presents valid corporate credentials.
The laptop has not received security updates for six months and its endpoint protection is disabled.
NAC can apply policy based on both identity and device condition.
Posture assessment asks: "what condition is the connecting device in?"
๐ช Pre-Admission & Ongoing Control Connection security does not necessarily stop after admission
Evaluate the user or device before granting normal network access.
Continue evaluating relevant conditions after access has already been granted.
A compliant laptop joins the network at 09:00.
Later, endpoint protection becomes disabled.
A more dynamic access-control architecture may change the device's access rather than assuming the 09:00 decision remains valid forever.
NAC Timing
๐ 802.1X Port-Based Access Control Control access before normal network communication begins
IEEE 802.1X is commonly used to control access to wired and wireless network infrastructure.
The endpoint requesting network access.
The network access device controlling the connection, such as a switch or wireless access point.
Validates authentication information and supports the access decision, often using AAA infrastructure such as RADIUS.
802.1X
๐ฆ NAC Enforcement Decisions Access does not have to be simply yes or no
Grant the access appropriate to the user and device.
Provide only limited network access.
Isolate the endpoint so remediation can occur without exposing the normal network.
Prevent network access when policy requirements are not satisfied.
A corporate laptop is missing a required security update.
Rather than providing full access or completely disconnecting it, NAC places it into a restricted environment where it can reach only:
NAC Decisions
โ๏ธ Physical & Virtual NAC Access control must follow modern network architecture
NAC is not limited to a user plugging a laptop into a physical Ethernet port.
Wired switch ports, wireless access and physical infrastructure can enforce admission decisions.
Access policies may also apply to virtual machines, cloud workloads, software-defined networks and virtual interfaces.
Determine whether a user, device or workload should communicate and what level of access is appropriate.
โ ๏ธ NAC Limitations Admission control does not replace endpoint security
A device can satisfy a posture check and later become compromised.
Knowing which user owns a laptop does not prove that every process on that laptop is trustworthy.
NAC controls access to network resources.
Host-based endpoint controls protect what happens on the endpoint itself.
The Host Is Part of the Network Security Architecture
An endpoint is a device that participates in the network and can become both a target and an attack platform.
Laptops and mobile devices frequently operate outside the traditional corporate network.
Host-based security therefore becomes especially important when the device is not protected by the organisation's network perimeter.
Endpoint Security Layers
๐ง Endpoint Hardening Reduce unnecessary attack surface
Define an approved secure configuration.
Keep operating systems and applications appropriately updated.
Remove network and application functionality that has no legitimate requirement.
Users and processes should receive only the permissions they need.
Unnecessary or insecure default access should not remain enabled.
Configure authentication, logging, encryption and other controls according to organisational requirements.
Restrict software execution where appropriate.
Manage removable storage and other peripheral interfaces according to risk.
Hardening
๐ฅ Host-Based Firewall Control network communication at the endpoint itself
A host firewall controls network traffic entering or leaving an individual endpoint.
A laptop is connected to a hotel Wi-Fi network.
The organisation's perimeter firewall is not between the laptop and every device on that local network.
The laptop's own firewall can still restrict unwanted inbound communication.
A network firewall protects traffic crossing a network boundary.
A host firewall applies policy directly at the endpoint.
Firewall Placement
๐ฆ Anti-Malware / Endpoint Protection Prevent and detect malicious software
Endpoint protection can combine multiple techniques to identify or prevent malicious activity.
Identify known malicious patterns.
Identify suspicious characteristics that may indicate malicious software.
Detect suspicious activity based on what a process attempts to do.
Consider information about files, software or sources.
Endpoint protection also depends on patching, configuration, privileges, firewalling, monitoring and data protection.
๐ Endpoint Detection & Response - EDR Observe endpoint behaviour and support investigation and response
EDR focuses on collecting endpoint security telemetry, detecting suspicious behaviour and supporting investigation and response.
EDR May Observe
Response Capabilities May Include
A user opens a malicious document.
A suspicious process launches a scripting engine and immediately connects to an unusual external host.
Behavioural endpoint telemetry can help security teams detect the sequence even if a simple file signature did not recognise the original document.
EDR
Endpoint Protection vs EDR
| Endpoint Protection | EDR | |
|---|---|---|
| Main Emphasis | Prevent malicious activity | Detect, investigate and respond |
| Typical Focus | Malware prevention and execution control | Behaviour and endpoint telemetry |
| Response | Block or quarantine threats | Investigate, isolate and contain |
For CISSP, understand the security functions rather than focusing on product labels.
๐จ Host-Based Detection & Prevention Observe activity from the perspective of the individual host
Host-based Intrusion Detection System monitors host activity and generates alerts when suspicious behaviour is identified.
Host-based Intrusion Prevention System can additionally attempt to prevent identified malicious activity.
Detection vs Prevention
๐ฉน Endpoint Patch & Vulnerability Management Known weaknesses should not remain indefinitely
An organisation cannot reliably patch an endpoint it does not know exists.
๐ค Least Privilege on Endpoints Compromise impact depends on what the user or process can do
Two users open the same malicious attachment.
User A operates with: standard-user permissions.
User B operates permanently with: local administrator permissions.
The same malicious code may have substantially greater opportunities when executed with higher privilege.
Endpoint compromise is still serious, but unnecessary privilege can make the consequences much worse.
๐ Endpoint Data Protection Protect information when a device is lost or stolen
Portable endpoints introduce a significant physical-loss risk.
Protect information stored across an endpoint's disk when the system is not appropriately authenticated.
Protect selected information rather than the complete storage volume.
Restrict or protect information copied to portable storage.
Endpoint data-loss-prevention controls can help identify or restrict inappropriate movement of sensitive information.
An employee leaves a laptop on a train.
Full-disk encryption can reduce the risk that someone who obtains the physical device can simply remove the disk and read its contents.
Once the legitimate operating system has unlocked the storage, additional controls are required to protect against malware or an attacker operating within that active session.
๐ฅพ Secure Boot & Trusted Startup Protect the system before the normal operating environment loads
Endpoint protection begins before a user logs in.
Security controls running inside the operating system are less useful if an attacker has already compromised lower-level startup components.
๐ฑ Central Endpoint Management Security policy must scale beyond one device
Organisations commonly use central management platforms to maintain endpoint configuration and security state.
Compromise of endpoint-management infrastructure can potentially give an attacker powerful control over many devices.
Network-Based vs Host-Based Security
| Network-Based | Host-Based | |
|---|---|---|
| Location | Network infrastructure | Individual endpoint |
| Visibility | Traffic visible at network observation point | Processes, files, local activity and endpoint traffic |
| Examples | Network firewall, network IDS/IPS, NAC | Host firewall, anti-malware, EDR, host IDS/IPS |
| Off Corporate Network | Some controls may no longer be directly in the traffic path | Host controls remain with the endpoint |
Network vs Host
Use both.
An Employee Connects a Laptop
An employee arrives at the office and connects a corporate laptop to the network.
Current patches + active endpoint protection + valid corporate certificate.
Normal authorised access.
Missing important security updates.
Restricted remediation access.
Cannot establish approved identity or satisfy access policy.
Deny or tightly restrict access.
A Laptop Is Compromised
A malicious attachment executes on an employee laptop.
A Laptop Is Stolen
Helps protect stored information while the device is offline and locked.
Makes unauthorised interactive access more difficult.
May support remote lock, revocation or wipe where technically possible and appropriate.
Device credentials may need to be invalidated.
A stolen endpoint should not automatically regain trusted access simply because it was previously approved.
The loss should be reported, assessed and managed according to organisational procedure.
๐ CISSP Scenarios Identify the relevant component or security principle
A core router still operates normally but no longer receives vendor security updates.
Primary concern?
End-of-support / infrastructure lifecycle risk.
A network device has two power supplies, but both are connected to the same electrical circuit.
Primary concern?
A shared upstream power dependency remains a single point of failure.
A backup firewall exists, but its configuration has never been synchronised or tested.
What is missing?
Tested operational failover.
Two WAN circuits from different providers enter the building through one conduit.
Primary concern?
Lack of true physical route diversity.
Copper network cabling runs beside powerful electrical machinery and experiences repeated signal errors.
Most relevant issue?
Electromagnetic interference.
An organisation needs transmission media resistant to electromagnetic interference.
Which medium is particularly suitable?
Fibre optic.
Management claims fibre-optic cable cannot be intercepted.
What is wrong?
Fibre reduces certain interception and interference risks, but physical tapping is still possible.
Corporate Wi-Fi can be received from the public car park.
Which concept does this demonstrate?
Wireless signal propagation extends beyond the physical building boundary.
An employee connects a corporate laptop and the network verifies both the employee's identity and the laptop's security state before granting normal access.
Which control?
Network Access Control - NAC.
A laptop is missing required security updates and is placed on a network that can reach only patching services.
Which NAC action?
Quarantine / restricted remediation access.
In an 802.1X design, the employee laptop is requesting network access.
Which role?
Supplicant.
A network switch controls whether the endpoint's port becomes authorised.
Which 802.1X role?
Authenticator.
A central AAA service validates authentication information presented during network admission.
Which 802.1X role?
Authentication server.
A corporate laptop passes NAC admission at 09:00 but becomes compromised at 11:00.
What lesson does this demonstrate?
Successful network admission does not guarantee continued endpoint trustworthiness.
A laptop connected to public hotel Wi-Fi blocks unsolicited inbound connections using a control installed directly on the device.
Which control?
Host-based firewall.
Security software records process creation, network connections and suspicious persistence activity on a workstation.
Which capability is most relevant?
Endpoint Detection and Response - EDR.
A suspicious workstation is remotely disconnected from normal network communication while investigators examine it.
Which endpoint-response action?
Endpoint isolation / containment.
A user normally performs office work using local administrator privileges.
Which security principle should be applied?
Least privilege.
A stolen laptop's drive cannot be read easily when removed from the device because stored data is cryptographically protected.
Which control?
Full-disk encryption.
Management claims disk encryption will stop malware from reading files while the user is logged in and the drive is unlocked.
Is this correct?
No. Disk encryption primarily protects stored data when appropriate authentication has not unlocked it.
An organisation centrally enforces device encryption, patching and security configuration across thousands of laptops.
Which approach?
Central endpoint management.
A network firewall blocks an attack at the data-centre boundary, but a travelling laptop is not currently behind that firewall.
What provides an additional local layer?
Host-based endpoint controls.
A device passes NAC because it has a valid certificate, but malware is already running on the endpoint.
What does this demonstrate?
Device admission and endpoint threat detection solve different security problems.
Administrative access to every router uses one shared account.
Primary problem?
Poor accountability and privileged-access management.
The network-management platform is compromised and used to push malicious configuration to hundreds of switches.
Which architectural lesson?
Central management improves efficiency but becomes a high-value security component requiring strong protection.
Recognise the Clue Words
Redundant PSU
Hardware availability.
Infrastructure ResilienceNo Vendor Updates
Equipment still works.
End of SupportBackup Device Never Tested
Installed but unproven.
Failover TestingTwo Links, Same Duct
Hidden shared dependency.
No Physical DiversityElectrical Interference
Copper signal problem.
EMI / RFISignals Interfere Between Cables
Adjacent conductors.
CrosstalkSignal Weakens with Distance
Transmission degradation.
AttenuationResistant to EMI
Light-based transmission.
FibreSignal Leaves Building
No cable boundary.
Wireless PropagationWho Can Join?
Network admission.
NACDevice Health
Patch, firewall, protection state.
Posture AssessmentFix Before Full Access
Limited remediation network.
Quarantine802.1X Client
Requests access.
Supplicant802.1X Switch / AP
Controls access.
Authenticator802.1X AAA Backend
Validates credentials.
Authentication ServerFirewall on Laptop
Local traffic control.
Host FirewallProcesses + Telemetry
Detect and investigate.
EDRKnown Malware
Endpoint prevention.
Anti-MalwareLost Laptop
Stored data protection.
Disk EncryptionUser Is Permanent Admin
Excessive privilege.
Least PrivilegeStandard Secure Configuration
Consistency across hosts.
Security BaselineOff Corporate Network
Protection remains on device.
Host-Based Securityโ ๏ธ Common CISSP Mistakes Think beyond the obvious device or product
A network component can remain operational after security updates, replacement parts and vendor support have ended.
Two devices may still depend on one switch, power source, cable route or provider.
Redundancy must be configured, maintained and tested.
Fibre offers important transmission advantages but physical access to the cable remains a security consideration.
Radio signals may propagate beyond the physical property.
Access decisions can consider identity, device posture and policy.
Identity and endpoint security state are different concepts.
NAC controls network access.
Host-based controls protect the endpoint itself.
One operates on an individual host while the other protects traffic at a network enforcement point.
Endpoint defence also requires patching, least privilege, configuration, firewalling and monitoring.
EDR focuses heavily on endpoint activity, telemetry, investigation and response.
Disk encryption protects stored information, particularly when the disk has not been legitimately unlocked.
Central management improves consistency but becomes a powerful and attractive attack target.
A compromised endpoint can become the attacker's platform for lateral movement.
Quick Reference
| If you see... | Think... |
|---|---|
| Network device no longer receives updates | End of Support |
| Two power supplies on one circuit | Shared Failure Point |
| Secondary device must take over | Failover |
| Two circuits in same duct | Lack of Physical Diversity |
| Electrical signal affected by machinery | EMI / RFI |
| Signals interfere between conductors | Crosstalk |
| Signal decreases over distance | Attenuation |
| Light-based transmission | Fibre Optic |
| Signal propagates outside building | Wireless Risk |
| Control whether device joins network | NAC |
| Evaluate patch / firewall / protection status | Posture Assessment |
| Limited network while device is repaired | Quarantine |
| 802.1X endpoint | Supplicant |
| 802.1X switch or AP | Authenticator |
| 802.1X backend identity check | Authentication Server |
| Firewall installed directly on endpoint | Host Firewall |
| Endpoint processes and behavioural telemetry | EDR |
| Detect known malicious software | Anti-Malware |
| Remove unnecessary host services | Hardening |
| User has more permissions than required | Least Privilege |
| Protect lost laptop storage | Disk Encryption |
| Standard configuration across endpoints | Security Baseline |
| Endpoint compromised while travelling | Host-Based Security |
Infrastructure Memory Aid
NAC Memory Aid
Identify โ Assess โ Decide โ Enforce โ Reassess
Endpoint Security Memory Aid
4.2 Master Memory Aid
Secure the component ยท Secure the path ยท Secure the connection ยท Secure the endpoint
Key Takeaways
Secure network architecture depends on securely operated infrastructure, protected transmission media, controlled network admission and host-based endpoint security.
Network components such as switches, routers, firewalls and controllers are themselves information systems and require hardening, patching, secure administration, logging and lifecycle management.
Administrative interfaces are especially sensitive because compromise of the network management plane can allow attackers to modify routing, filtering and other security behaviour.
Redundant power supplies, devices and links can improve availability, but true resilience requires avoiding shared dependencies.
Two components do not provide meaningful redundancy if both depend on the same power supply, physical path or upstream service.
Failover should be maintained and tested rather than assumed to work because duplicate equipment exists.
Warranty, technical support, replacement availability and end-of-support status are security concerns because unsupported infrastructure becomes harder to patch and recover.
Copper, fibre and wireless transmission media have different security and signal-quality characteristics.
Copper can be affected by electromagnetic interference, radio-frequency interference, crosstalk and attenuation.
Fibre uses light and is resistant to electromagnetic interference, but it still requires physical protection and can still be physically intercepted or damaged.
Wireless signals can extend beyond physical organisational boundaries and therefore require appropriate authentication, encryption and monitoring.
Physical route diversity matters because apparently separate network links can still fail together if they share one cable duct or physical path.
Network Access Control determines whether users and devices should receive network access and what level of access is appropriate.
NAC can evaluate identity and device posture and then allow, restrict, quarantine or deny access.
In 802.1X, the supplicant requests access, the authenticator controls the connection and the authentication server validates authentication information.
Successful NAC admission does not prove that an endpoint will remain uncompromised throughout its session.
Host-based security therefore remains necessary even when NAC and strong network controls are present.
Endpoint hardening reduces attack surface by applying secure baselines, patching, least privilege and removal of unnecessary functionality.
Host firewalls enforce network policy directly on an endpoint and remain valuable when the device operates outside the traditional corporate perimeter.
Anti-malware helps identify and prevent malicious software but should be one part of a wider endpoint defence strategy.
EDR provides endpoint telemetry that supports behavioural detection, investigation and response.
Endpoint isolation can help contain a compromised host while investigation takes place.
Full-disk encryption is particularly valuable when endpoints are lost or stolen, but it does not replace malware protection when a legitimate session has already unlocked the disk.
Central endpoint-management systems help enforce consistent security policy but should themselves be treated as high-value administrative infrastructure.
Network-based and host-based controls provide different visibility and enforcement points and are most effective when used together.
The CISSP principle is simple: secure the infrastructure carrying the traffic, protect the medium carrying the signal, control which devices may connect and continue protecting the endpoint after it is connected.
๐ Sources & Further Reading Network components, NAC and endpoint-security references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-215 - Guide to a Secure Enterprise Network Landscape
View NIST enterprise network guidance - NIST - Network Access Control Glossary
View the NIST NAC definition - NIST SP 800-41 Rev. 1 - Guidelines on Firewalls and Firewall Policy
View NIST firewall guidance - NIST SP 800-83 Rev. 1 - Guide to Malware Incident Prevention and Handling for Desktops and Laptops
View NIST endpoint malware guidance - NIST SP 800-111 - Guide to Storage Encryption Technologies for End User Devices
View NIST endpoint storage-encryption guidance - NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks
View NIST wireless-network guidance
