What is the difference between physical and virtual isolation, and which is weaker?
Physical isolation separates the system spatially, from all networks, removable media and exchange interfaces; virtual isolation uses anything that can prevent communication, such as VLANs, deny-all firewall rules or isolated subnets. Virtual isolation is weaker because it is more prone to misconfiguration.
Physical isolation:
- spatial separation,
- disconnected from all network connections,
- no removable media (memory sticks, CDs, diskettes…),
- no exchange interfaces (USB ports, serial ports…).
Depending on how strictly it is implemented, exchange is prevented by the means not existing ("not present"), being disabled ("not activated") or by organisational instruction ("do not use"). Physical isolation turns part of cyber security into physical security: walls, doors and fences replace IT permissions and restrictions.
Virtual isolation: Layer 2 VLANs, deny-all rules in firewalls, isolated subnets and so on. Because it depends on configuration, it is more prone to misconfiguration. In high-security scenarios where autonomous (self-sufficient) operation must be guaranteed, virtual isolation may not be accepted as a full equivalent.