Back to catalog
NET-03.8NETNetwork Security
Separate Subnet for Connecting to Different Security Domains
Description
Mechanisms exist to implement separate network addresses (e.g., different subnets) to connect to systems in different security domains.
Cross-Mappings
55 paths across 3 frameworks
Cross-Mappings
NIST 800-532 mappings
CCI5 mappings
CCI-002416
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004891
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004892
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001119
0.13
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001120
0.13
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · related
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG45 mappings
SV-220641r991848_ruleThe Cisco switch must have all disabled switch ports assigned to an unused VLAN.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R1 · disa_xccdf · related
SV-220642r991849_ruleThe Cisco switch must not have the default VLAN assigned to any host-facing switch ports.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R1 · disa_xccdf · related
SV-220643r991850_ruleThe Cisco switch must have the default VLAN pruned from all trunk ports that do not require it.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R1 · disa_xccdf · related
SV-220645r991853_ruleThe Cisco switch must have all user-facing or untrusted ports configured as access switch ports.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R1 · disa_xccdf · related
SV-220646r991854_ruleThe Cisco switch must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R1 · disa_xccdf · related
SV-220647r991855_ruleThe Cisco switch must not have any switchports assigned to the native VLAN.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R1 · disa_xccdf · related
SV-220667r991904_ruleThe Cisco switch must have all disabled switch ports assigned to an unused VLAN.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R2 · disa_xccdf · related
SV-220668r991905_ruleThe Cisco switch must not have the default VLAN assigned to any host-facing switch ports.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R2 · disa_xccdf · related
SV-220669r991906_ruleThe Cisco switch must have the default VLAN pruned from all trunk ports that do not require it.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R2 · disa_xccdf · related
SV-220671r991908_ruleThe Cisco switch must have all user-facing or untrusted ports configured as access switch ports.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V3R2 · disa_xccdf · related
+35 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer