Why is security-by-isolation a suitable choice for the BGP summer boot camp and for a malware-analysis environment?
Both need to keep something from getting out: the boot camp deliberately provokes routing failures that must not reach other networks or the internet, and the analysis environment must contain suspicious software. In both, the system boundary serves as breakout protection, and in the boot camp the missing patches and backups are an acceptable risk because the setup is temporary and not productive.
BGP boot camp (university H): for two weeks, student teams build autonomous systems with BGP routers and Linux machines, connect them, and then deliberately provoke faults and outages. Isolation keeps the learning environment realistic, prevents disruption of other networks including the internet, and above all prevents a breakout during the fault phase. Because the setup is short-lived (two weeks), not a production environment and dismantled afterwards, the risk of missing security patches, backup and recovery can be carried.
Security company S boots infected or suspicious devices and analyses suspicious software in a virtual isolation environment. Here the system boundary serves as breakout protection (containment).
Tip: Isolation fits best when the danger comes from inside and must not get out, and when the system does not need the operational services that isolation cuts off.