VLAN
What is VLAN?
Virtual Local Area Network, a logical network segment created within a physical network to isolate traffic and improve security through network segmentation.
Terms that appear alongside vlan
Each of these is named in at least one of the same controls as vlan. The number is how many controls name both.
- firewall 4 shared controls
- gateway 4 shared controls
- zero trust 3 shared controls
- microsegmentation 3 shared controls
- defense in depth 3 shared controls
- dnssec 3 shared controls
- dmz 3 shared controls
- network architecture 2 shared controls
Frameworks that govern vlan
What the standards actually require on vlan
Requirements naming vlan across 6 standards, quoted from the control text.
Network devices managing VLANs are administered from the most trusted security domain.
ISM-0530 · Network devices managing VLANs are administered from the most trusted security domain. →Security Layer 1 Infrastructure per X.805 Clause 7.1: The Infrastructure Security Layer consists of network facilities (transmission facilities and network elements) protected by the security measures.
X805-Layer1-Infrastructure-Security-Transmission-Facilities-Network-Elements-Lines-Routers-Switches · ITU-T X.805 Security Layer 1 - Infrastructure Security + Transmission Facilities + Network Elements + Routers + Switches + Lines + Physical + Datacenter + Optical + Radio Access + Wireless + Wireline + Edge →Design ICS network architecture using defined zones, a demilitarised zone (DMZ) between the control network and the corporate/enterprise network, and VLAN segmentation to separate functions and contain compromise.
CISA-ICS-DID-24 · ICS Network Architecture →Security for IEC 61850 protocol profiles using VLAN marks and X.509 signatures on GOOSE and SMV telegrams
62351-6 · Security for IEC 61850 profiles →Protect is the second of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Access Control - identity and access management for IT + OT systems + role-based access + least privilege + privileged access management (PAM) for OT engineer...
IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity · IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media →Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection...
KNCF-Protect-Network-Configuration-Vulnerability-Physical-Secure-SDLC-Hardening-Patching-Drift · Kuwait NCF Protect + Network + Configuration + Vulnerability + Physical + Secure SDLC →Questions people ask about vlan
What is VLAN?
Why is VLAN important for compliance?
Which compliance frameworks address VLAN?
Where can I learn more about VLAN?
See how VLAN applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.