This article provides a complete hardening framework mapped to specific SOC2 Trust Services Criteria (CC6, CC7, CC8) and ISO 27001 Annex A controls, along with Cisco IOS configuration templates for a 3850 on 16. 9 that satisfy these requirements without requiring a software upgrade. Also, this guide can assist information security officers by describing the security issues related to critical systems (e., switches) which are part of their computer networks. This guide was developed in response to numerous questions and requests for assistance received by the Systems and. The short answer: IOS software updates are not required to maintain compliance with SOC2, ISO 27001, or PCI DSS on Cisco access-layer switches. Compliance is achievable — and fully defensible in an audit — through deliberate LAN configuration hardening: enforcing least privilege, strong. Step 1: Create a Secure Trunk. Step 2: Secure Unused Switchports. Secure Access to the Switch Use Strong Passwords: Configure strong, unique passwords for all switch accounts, avoiding default or weak credentials. Enable SSH: Disable insecure protocols like Telnet and enable. This command produces the boot loader prompt (switch:) after the switch is power cycled.