Skip to content

Sandboxing

What is Sandboxing?

A security technique that isolates running programs or processes in a restricted environment to prevent them from affecting other parts of the system.

Information Security

Each of these is named in at least one of the same controls as sandboxing. The number is how many controls name both.

What the standards actually require on sandboxing

Requirements naming sandboxing across 6 standards, quoted from the control text.

MITRE D3FEND2 controls

Apply D3FEND ISOLATE tactic to create logical or physical barriers in a system to reduce attack opportunities and impact. D3-EI Execution Isolation (D3-HBPI Hardware-based Process Isolation + D3-SCF System Call Filtering + D3-IBCA IO Channel Authentication + D...

MITRE-D3FEND-Isolate-Tactic-Execution-Network-Isolation-Sandboxing-Microsegmentation-DNS-Filtering · MITRE D3FEND Isolate Tactic + Execution + Network Isolation + Sandboxing + Microsegmentation + DNS Filtering

As an alternative or supplement to signature anti malware, organisations may use application allow listing or sandboxing to prevent execution of unauthorised code.

CEP-MA-02 · Application Allow Listing or Sandboxing

Runs vetted applications or processes in sandboxed compartments on the asset, isolating them from the rest of the device and from local attacks.

SP800-207-DEP-SANDBOX · Device Application Sandboxing

Continuous Monitoring + Lifecycle Management is essential to ongoing trustworthy AI per Japan AI Guidelines for Business + integrates Safety + Accountability + Transparency Principles + addresses post-deployment risks.

JP-AIG-Continuous-Monitoring-Lifecycle-Model-Evaluation-Performance-Drift-Post-Deployment · Japan AI Guidelines Continuous Monitoring + AI System Lifecycle Management + Model Evaluation + Performance Drift + Concept Drift + Post-Deployment + Retraining Triggers + Safe Update + Decommissioning + Model Card Versioning

Deploy and maintain email server anti-malware protections, such as attachment scanning and/or sandboxing.

CIS-9.7 · Deploy and Maintain Email Server Anti-Malware Protections

Secure runtime compute: host/node hardening, orchestrator security, container runtime isolation (sandboxing, seccomp/AppArmor) and microservice protection.

CNCF-RT-COMPUTE · Runtime Compute Security (Orchestration, Hosts, Containers)

Questions people ask about sandboxing

What is Sandboxing?
A security technique that isolates running programs or processes in a restricted environment to prevent them from affecting other parts of the system.
Why is Sandboxing important for compliance?
Sandboxing is a key concept in Information Security. Understanding sandboxing helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Sandboxing?
Sandboxing appears in the requirement text of MITRE D3FEND, Cyber Essentials Plus, NIST SP 800-207, Japan AI Guidelines, CIS Controls v8. Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Sandboxing?
Explore our compliance framework pages to see how sandboxing applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Sandboxing applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.