It is very easy to do, but can cause some havoc on an already overtaxed network. One thought is that an attacker won't hesitate to do it, so you should as well. However, we also have to be concerned about the sensitive 24/7 systems they may have running. I have seen instances where after a reboot, switches reverted back to older configurations. (I tend to think the config wasn't saved to flash, but that's me.)
Is there a better way? Can you effectively sniff traffic from a switched network without ARP poisoning?