CICB in national-laboratory environments
National laboratories may evaluate CICB as a Windows endpoint visual-banner component for selected classified, CUI, research, administrative, or isolated-LAN workstations.
Authoritative guidance comes first
The laboratory security classification guide, information owner, DOE or sponsoring-agency directives, NARA CUI Registry, contracts, and authorization boundary determine the required markings and safeguards. CICB does not establish DOE or NIST compliance.
Evaluation checklist
- Identify the approved marking text, classification authority, and system boundary.
- Limit claims to supported Windows endpoints; do not infer Linux HPC or terminal support from historical prototypes.
- Test multi-monitor, KVM, VDI, scaling, startup, offline, stale-policy, and failure behavior.
- Assign responsibility for identity, PKI, audit, SIEM, immutable records, ACLs, offline transfer, and incident response.
- Verify the signed release, dependencies, SBOM/VEX, installed files, network paths, and operational configuration.
Historical claims about laboratory deployments, WORM logs, context detection, Linux packages, SIEM exports, audit results, and ROI are not verified customer evidence.
