Lab authorisation, topology, and safety
Set the scope before starting a lab. Use the supplied synthetic or sanitised records, calculations and local simulations, with no connection to operational equipment.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Offline research and planning only; product or deployment acceptance belongs to separately governed environment validation.
On this page
Overview#
Lab class: Offline fixture, calculation, tabletop, simulated topology, or loopback simulation
Required record#
Before beginning a lab, record:
- provenance, ownership, and authority for every fixture, capture, dataset, and licensed source;
- lab class from the permitted set in the section policy;
- exact fixture names, digests, versions, synthetic identities, and tools;
- for loopback simulation, bindings and evidence that no external route, proxy, discovery path, or device contact exists;
- permitted processing and data handling scope;
- prohibited operations, especially network contact, writes, actuation, availability tests, firmware changes, and credential use;
- content hazards, including personal data, secrets, live identifiers, malicious artefacts, and licensed material;
- time window, reviewer, evidence location, and disposal requirements;
- expected observations and stop conditions;
- cleanup, fixture disposal, and restoration of the local analysis environment.
Stop conditions#
Stop immediately if scope or provenance is uncertain; any non loopback traffic appears; a fixture contains an unexpected secret, personal record, live credential, or operational identifier; loopback confinement fails; an action would require device, broker, receiver, endpoint, field bus, or hardware contact; or cleanup can't be guaranteed.
Isolation principles#
Prefer embedded fixtures and calculations. When a loopback simulation materially helps, bind every component exclusively to operating system loopback, use synthetic identities, disable proxy/discovery behaviour, and verify confinement before processing the fixture. Private address space, a dedicated switch, a VLAN, or a serial adapter isn't loopback and doesn't make hardware eligible for this lab section.
Evidence checklist#
- Permitted lab class selected and scope recorded
- Fixture provenance, authority, digest, version, and sensitivity recorded
- Synthetic identities and non operational data confirmed
- Loopback only binding and absence of external routes confirmed where simulation is used
- Stop conditions, prohibited actions, and cleanup responsibilities assigned
- Evidence location, retention, sharing, and disposal rules recorded
- Physical or operational acceptance work routed to the separate environment validation process