Defensive labs About 2 min read

Lab authorisation, topology, and safety

Set the scope before starting a lab. Use the supplied synthetic or sanitised records, calculations and local simulations, with no connection to operational equipment.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Offline research and planning only; product or deployment acceptance belongs to separately governed environment validation.

Verification and testing

Overview#

Lab class: Offline fixture, calculation, tabletop, simulated topology, or loopback simulation

Required record#

Before beginning a lab, record:

  • provenance, ownership, and authority for every fixture, capture, dataset, and licensed source;
  • lab class from the permitted set in the section policy;
  • exact fixture names, digests, versions, synthetic identities, and tools;
  • for loopback simulation, bindings and evidence that no external route, proxy, discovery path, or device contact exists;
  • permitted processing and data handling scope;
  • prohibited operations, especially network contact, writes, actuation, availability tests, firmware changes, and credential use;
  • content hazards, including personal data, secrets, live identifiers, malicious artefacts, and licensed material;
  • time window, reviewer, evidence location, and disposal requirements;
  • expected observations and stop conditions;
  • cleanup, fixture disposal, and restoration of the local analysis environment.

Stop conditions#

Stop immediately if scope or provenance is uncertain; any non loopback traffic appears; a fixture contains an unexpected secret, personal record, live credential, or operational identifier; loopback confinement fails; an action would require device, broker, receiver, endpoint, field bus, or hardware contact; or cleanup can't be guaranteed.

Isolation principles#

Prefer embedded fixtures and calculations. When a loopback simulation materially helps, bind every component exclusively to operating system loopback, use synthetic identities, disable proxy/discovery behaviour, and verify confinement before processing the fixture. Private address space, a dedicated switch, a VLAN, or a serial adapter isn't loopback and doesn't make hardware eligible for this lab section.

Evidence checklist#

  • Permitted lab class selected and scope recorded
  • Fixture provenance, authority, digest, version, and sensitivity recorded
  • Synthetic identities and non operational data confirmed
  • Loopback only binding and absence of external routes confirmed where simulation is used
  • Stop conditions, prohibited actions, and cleanup responsibilities assigned
  • Evidence location, retention, sharing, and disposal rules recorded
  • Physical or operational acceptance work routed to the separate environment validation process

Section overview · Wiki home