E-Learning systems should be based on systematic pedagogical approaches and well-designed procedures and techniques. However, current literature on several areas of technology-enhanced learning environments, such as online information security (InfoSec) laboratories, may still lack well-specified pedagogical approaches and concrete design principles. In information security education, hands-on lab exercises play a major role in learning. Distance education brings in new challenges as the hands-on exercises require now virtual labs, which need to be accessible anywhere and often also anytime. This creates technological and pedagogical challenges, which are not fully understood in terms of explicit design principles that would enhance implementation and use of on-line educational labs. To contribute to this knowledge gap the paper based on the interviews, observations, and literature review formulates and describes five initial design principles: contextualization, collaboration, flexibility, cost-effectiveness, and scalability. The initial concretization of the principles adopts the pedagogical approach of Personalized System of Instruction (PSI), which is deemed to represent a good fit to the contextual goals for developing on-line security labs in the context of the target university. Further research for actual design of virtual InfoSec labs, adopting the action design-based research tradition to develop learning environments, is needed in order to concretize, to test and to elaborate these design principles.