What air-gapped actually means when a vendor says it
6 min read
Air-gapped can mean different things. These four questions establish what an installation actually needs from outside your network.
6 min read
Air-gapped can mean different things. These four questions establish what an installation actually needs from outside your network.
Licensing is the first question to ask. A platform whose licence check requires an outbound call is not air-gapped, whatever the deployment guide says, because renewal will fail in an environment with no route out.
The workable answer is a signed licence file. You generate a request on the installation, carry it out on removable media, and carry a signed licence back in. TrustPoint signs both with Ed25519 and node-locks the result, so the file cannot be replayed onto a second installation.
A GRC platform is only useful while its framework library is current. If new content arrives only through a live sync, an air-gapped site freezes on the day it was installed and quietly falls behind every published revision.
The workable answer is the same signature machinery. Content packs are versioned and signed, connected sites sync them daily, and an air-gapped site installs the identical signed pack by manual upload. The signature is what makes an offline path safe rather than a hole: the installation verifies the pack came from where it claims before applying it.
Continuous control monitoring is where an on-premises installation can leave your network without anyone noticing. If the connector that reads your identity provider runs in the vendor’s cloud, then your directory credentials left the building and the posture data went with them.
Ask directly: where does the connector execute, what can it reach, and where is the credential stored? In TrustPoint, connectors run inside the platform, so in an on-premises or air-gapped installation they run on your network, and each connection can reach only the hosts on its allowlist. Secrets are encrypted and stored per tenant.
This is the newest version of the question and the one most likely to be answered vaguely. An assistant that reads your risk register and sends it to a model somebody else operates has moved your most sensitive register outside your control, whatever the data-processing addendum says.
The workable answer is that you choose the provider and it is verified for your tenant, including a model running entirely inside your own network, and that the assistant stays disabled until that is done. Then ask where prompts are processed and what is retained, because that depends on the provider you pick.
Many Gulf organizations run three or four overlapping frameworks. The overlap is real, the saving is real, and claiming it badly is how a programme acquires findings.
The screenshot taken the week of the audit is the defining artefact of point-in-time compliance, and the reason so many programmes fail their second year.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.