Sandbox
What is Sandbox?
An isolated testing environment that enables users to run programs or execute code without affecting the rest of the system. In security, sandboxes are used to safely analyse suspicious files and malware.
Terms that appear alongside sandbox
Each of these is named in at least one of the same controls as sandbox. The number is how many controls name both.
- consent 8 shared controls
- compliance 8 shared controls
- regulatory sandbox 7 shared controls
- audit 5 shared controls
- governance 4 shared controls
- cybersecurity 4 shared controls
- breach notification 4 shared controls
- information security 4 shared controls
Frameworks that govern sandbox
What the standards actually require on sandbox
Requirements naming sandbox across 6 standards, quoted from the control text.
Art.57 requires each Member State to establish at least one AI regulatory sandbox and sets what it must provide. Art.58 directs the Commission to adopt implementing acts on the detailed arrangements for sandboxes and lists what those arrangements must cover.
EUAI-Art.57-63 · AI regulatory sandboxes and measures for SMEs (Arts 57, 58, 62 and 63) →Non-persistent virtualised sandboxed environment for risky activities such as processing untrusted documents and web browsing.
ASD37-24 · Non-persistent virtualised sandboxed environment (Very Good) →Executable files imported via gateways or CDSs are automatically executed in a sandbox to detect any suspicious behaviour.
ISM-1389 · Executable files imported via gateways or CDSs are automatically executed in a sandbox to →Apply D3FEND ISOLATE tactic to create logical or physical barriers in a system to reduce attack opportunities and impact. D3-EI Execution Isolation (D3-HBPI Hardware-based Process Isolation + D3-SCF System Call Filtering + D3-IBCA IO Channel Authentication + D...
MITRE-D3FEND-Isolate-Tactic-Execution-Network-Isolation-Sandboxing-Microsegmentation-DNS-Filtering · MITRE D3FEND Isolate Tactic + Execution + Network Isolation + Sandboxing + Microsegmentation + DNS Filtering →Regulatory sandbox. Article 38 empowers the authority to authorise experimental regulatory environments (sandboxes) for AI innovation under supervision.
BRAI-A38 · Regulatory sandbox →As an alternative or supplement to signature anti malware, organisations may use application allow listing or sandboxing to prevent execution of unauthorised code.
CEP-MA-02 · Application Allow Listing or Sandboxing →Questions people ask about sandbox
What is Sandbox?
Why is Sandbox important for compliance?
Which compliance frameworks address Sandbox?
Where can I learn more about Sandbox?
See how Sandbox applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.