If you leave it open anyone will be able to connect, AFAIK you cannot run VirtualAPs and disable the “hardware” one, so you’ll have to:
a) Move any of the virtualAPs to the “hardware SSID”
b) If you’re going to use that SSID, you could either:
Use security (WPA2 EAP with a strong key will do) .
You could prevent its use with deselecting “default authenticate” and “default forward” so that no one (unless the mac is listed in Access List with proper authentication and forward defaults) will be able to connect to it.