Layer 2 Switch SRG Version Comparison
Layer 2 Switch Security Requirements Guide
Comparison
There are 4 differences between versions v2 r1 (May 18, 2021) (the "left" version) and v3 r2 (April 2, 2025) (the "right" version).
Check SRG-NET-000715-L2S-000120 was added to the benchmark in the "right" version.
This check's original form is available here.
Text Differences
Title
The layer 2 switch must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions.
Check Content
Verify the layer 2 switch is configured to implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions. If the layer 2 switch is not configured to implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions, this is a finding.
Discussion
Separating critical system components and functions from other noncritical system components and functions through separate subnetworks may be necessary to reduce susceptibility to a catastrophic or debilitating breach or compromise that results in system failure. For example, physically separating the command and control function from the in-flight entertainment function through separate subnetworks in a commercial aircraft provides an increased level of assurance in the trustworthiness of critical system functions.
Fix
Configure the layer 2 switch to implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions.