I read the level 3 requirement to require control of the Access Point (AP) - But it seems that C3PAOs are certifying organizations that use ZT-VPN on endpoints as sufficient to meet. Am I reading the requirement correctly ? I get that the endpoint must be encrypted but is control of the AP to be ignored just because the endpoint meets the requirements ?
[link] [comments]