Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Air-gapped device labs: what regulated teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20026
Topic starter  

TL;DR: Air-gapped and network-restricted enterprises can run full-stack, automated device testing entirely on-premises while preserving compliance, observability, and scale, according to Arxan Technologies. The practical shift is to treat the lab as part of the controlled environment, not a compromise, because governance, auditability, and toolchain integration matter more than remote convenience.

NHIMG editorial — based on content published by Arxan Technologies: Air-Gapped Testing Without Tradeoffs: Secure & Scalable

Questions worth separating out

Q: How should regulated teams govern access to on-premise device labs?

A: Treat device labs like any other privileged environment.

Q: Why do remote testing platforms struggle in air-gapped environments?

A: They depend on external infrastructure and data paths that conflict with requirements to keep regulated data, device telemetry, and validation records inside the enterprise boundary.

Q: What breaks when test artefacts are not preserved as audit evidence?

A: You lose the ability to prove what was tested, what failed, and what conditions existed at the time.

Practitioner guidance

  • Define the test estate as a controlled environment Classify device labs, test artifacts, and execution infrastructure as governed assets, with explicit ownership, access review, and retention rules aligned to the regulated workload.
  • Restrict privileged lab administration Limit lab administration to named roles, require step-up approval for broad device or pipeline access, and separate build-trigger permissions from artifact access.
  • Integrate evidence handling into validation workflows Store logs, screenshots, video, and network captures in systems that support integrity, retention, and traceability so they can be used for audit and root-cause analysis.

What's in the full article

Arxan Technologies' full article covers the operational detail this post intentionally leaves for the source:

  • Deployment patterns for standing up an on-premise device lab inside restricted networks
  • Examples of parallel execution and scheduler design across mixed device estates
  • Integration details for CI/CD, test management, and observability platforms
  • Artifact handling approaches for audit trails, crash reports, and network captures

👉 Read Arxan Technologies' analysis of air-gapped testing without tradeoffs →

Air-gapped device labs: what regulated teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19617
 

Air-gapped testing should be treated as a control-boundary design problem, not a tooling limitation. The article shows that the real issue is whether testing infrastructure can operate inside the same governance perimeter as the regulated system under test. That makes the boundary itself part of the assurance model, with implications for access control, auditability, and evidence retention. For identity and security teams, the lesson is that control placement matters as much as test automation coverage.

A question worth separating out:

Q: What is the difference between a device lab and a controlled validation environment?

A: A device lab is the physical and software setup used to run tests. A controlled validation environment adds governance, access restrictions, retention rules, and evidence handling so the lab can support compliance and audit expectations, not just engineering convenience.

👉 Read our full editorial: Air-gapped testing can scale without sacrificing auditability



   
ReplyQuote
Share: