Skip to content

Sandbox

What is Sandbox?

An isolated testing environment that enables users to run programs or execute code without affecting the rest of the system. In security, sandboxes are used to safely analyse suspicious files and malware.

Information Security

Each of these is named in at least one of the same controls as sandbox. The number is how many controls name both.

What the standards actually require on sandbox

Requirements naming sandbox across 6 standards, quoted from the control text.

EU AI Act4 controls

Art.57 requires each Member State to establish at least one AI regulatory sandbox and sets what it must provide. Art.58 directs the Commission to adopt implementing acts on the detailed arrangements for sandboxes and lists what those arrangements must cover.

EUAI-Art.57-63 · AI regulatory sandboxes and measures for SMEs (Arts 57, 58, 62 and 63)

Non-persistent virtualised sandboxed environment for risky activities such as processing untrusted documents and web browsing.

ASD37-24 · Non-persistent virtualised sandboxed environment (Very Good)

Executable files imported via gateways or CDSs are automatically executed in a sandbox to detect any suspicious behaviour.

ISM-1389 · Executable files imported via gateways or CDSs are automatically executed in a sandbox to
MITRE D3FEND2 controls

Apply D3FEND ISOLATE tactic to create logical or physical barriers in a system to reduce attack opportunities and impact. D3-EI Execution Isolation (D3-HBPI Hardware-based Process Isolation + D3-SCF System Call Filtering + D3-IBCA IO Channel Authentication + D...

MITRE-D3FEND-Isolate-Tactic-Execution-Network-Isolation-Sandboxing-Microsegmentation-DNS-Filtering · MITRE D3FEND Isolate Tactic + Execution + Network Isolation + Sandboxing + Microsegmentation + DNS Filtering

Regulatory sandbox. Article 38 empowers the authority to authorise experimental regulatory environments (sandboxes) for AI innovation under supervision.

BRAI-A38 · Regulatory sandbox

As an alternative or supplement to signature anti malware, organisations may use application allow listing or sandboxing to prevent execution of unauthorised code.

CEP-MA-02 · Application Allow Listing or Sandboxing

Questions people ask about sandbox

What is Sandbox?
An isolated testing environment that enables users to run programs or execute code without affecting the rest of the system. In security, sandboxes are used to safely analyse suspicious files and malware.
Why is Sandbox important for compliance?
Sandbox is a key concept in Information Security. Understanding sandbox helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Sandbox?
Sandbox appears in the requirement text of EU AI Act, ASD Strategies to Mitigate Cyber Security Incidents, Australian Information Security Manual, MITRE D3FEND, Brazil AI Framework. Across these standards we have identified 12 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Sandbox?
Explore our compliance framework pages to see how sandbox applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Sandbox applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.