The layer 2 switch must have all disabled switch ports assigned to an unused VLAN.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-206666SRG-NET-000512-L2S-000007SV-206666r385561_ruleCCI-000366medium
Description
It is possible that a disabled port that is assigned to a user or management VLAN becomes enabled by accident or by an attacker and as a result gains access to that VLAN as a member.
STIGDate
Layer 2 Switch Security Requirements Guide2025-03-05

Related Frameworks

4 paths across 3 frameworks
NIST 800-531 mapping
CM-6
1.00
  • DISA · 3 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1712 mappings
3.4.1
1.00
  • DISA · 3 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.4.2
1.00
  • DISA · 3 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-000366
1.00
  • DISA · 3 · disa_xccdf · related

Details

Check Text (C-206666r385561_chk)

Review the switch configurations and examine all access switch ports. Each access switch port not in use should have membership to an inactive VLAN that is not used for any purpose and is not allowed on any trunk links. If there are any access switch ports not in use and not in an inactive VLAN, this is a finding. Note: Switch ports configured for 802.1x are exempt from this requirement.

Fix Text (F-6924r298429_fix)

Assign all switch ports not in use to an inactive VLAN. Note: Switch ports configured for 802.1x are exempt from this requirement.