ASD ISM 1318Keep SSID Broadcasting Enabled on Wireless Access Points
SSID broadcasting must be left enabled on wireless access points and not disabled, because hiding the network name gives no real security benefit.
Plain language
This control ensures that SSID broadcasting stays enabled on your wireless access points rather than being switched off. Turning off SSID broadcasting is often thought to hide a network, but the network name can still be found easily with freely available tools, so it offers only a false sense of security. Hiding the SSID can also cause connection problems and make devices repeatedly search for the network, which can expose those devices. Leaving broadcasting enabled keeps wireless connections reliable, while genuine protection comes from strong encryption and authentication.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Mar 2022
Control Stack last updated
10 Aug 2026
E8 maturity levels
N/A
Official control statement
SSID broadcasting is not disabled on wireless access points.
Why it matters
If SSID broadcasting is disabled, the organisation gains no genuine security benefit while risking connectivity problems and causing devices to continually probe for the hidden network, which can expose those devices.
Operational notes
Include the SSID broadcasting setting in routine wireless configuration reviews so it is not accidentally disabled during firmware upgrades or new deployments.
Implementation tips
- Network administrators should check the configuration of every wireless access point and confirm that the option to hide or disable the SSID is turned off, so broadcasting stays on.
- IT staff should re-enable SSID broadcasting on any access point where it was previously disabled, applying the change through the access point management console or wireless controller.
- Administrators should build a standard wireless configuration or controller profile that has SSID broadcasting enabled, so new access points are deployed with broadcasting on by default.
- IT teams should configure strong wireless encryption and authentication such as WPA2 or WPA3 on each access point, relying on these controls rather than on hiding the SSID.
- Administrators should record SSID broadcasting enabled as a mandatory setting in the wireless build standard and verify it during change management for any access point changes.
Audit / evidence tips
- AskAsk the network team to show the SSID broadcasting setting on a representative sample of wireless access points.GoodEvery sampled access point has SSID broadcasting enabled, with no hidden or disabled SSID.
- AskAsk for the organisation's documented wireless configuration standard or build template.GoodThe standard clearly requires SSID broadcasting to remain enabled and does not call for hiding the SSID.
- AskAsk how new wireless access points are provisioned and configured before deployment.GoodProvisioning applies profiles with broadcasting enabled, so new access points are never deployed with the SSID disabled.
- AskAsk what controls protect the wireless network in place of hiding the SSID.GoodAccess points use strong encryption and authentication such as WPA2 or WPA3, showing security does not depend on a hidden SSID.
- AskAsk for evidence that any access points with a previously disabled SSID have had broadcasting restored.GoodChange records confirm SSID broadcasting was re-enabled wherever it had been disabled, with no outstanding hidden SSIDs.
Cross-framework mappings
How ISM-1318 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.20 | ISM-1318 requires organisations to harden wireless access points by disabling SSID broadcasting to reduce wireless network discoverability | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Networking
See all Guidelines for networking controls, or browse the full ASD ISM library.