Singapore SASH — Detecting Offensive Cyber Agents (Defence-in-Depth)
Singapore SASH — Detecting Offensive Cyber Agents (Defence-in-Depth) — 31% of in-scope requirements covered.
4 requirements · 4 in scope (1 designed · 3 advisory). The 31% is weighted over the in-scope base.
Source: Singapore SASH (Security Alert Standard / Honeypots) — 'Detecting Offensive Cyber Agents' defence-in-depth framework (2026): agent identity mechanisms, agent honeypots, automated alert/triage, a security alert standard, and the Agentic Cybersecurity Exchange (ACE). KYE Protocol™ governs the AUTHORITY, IDENTITY and EVIDENCE of agent actions — it makes a defending organisation's own agents first-class, identifiable principals whose actions are replay-provable, complementing detection-in-depth. KYE™ is not an intrusion-detection / honeypot product; it is the authority + evidence substrate the identity and alert layers assume. Starter requirement set; deepen by graft through the §70 rail. · License: SASH materials are Singapore-government publications; KYE™ registry paraphrases each mechanism's intent and cites the mechanism identifier for mapping purposes only.
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| Agent identity | 1 | 0 | 1 | 0 | 0 | 50% |
| Detection & triage | 1 | 0 | 0 | 1 | 0 | 25% |
| Alert standard & exchange | 1 | 0 | 0 | 1 | 0 | 25% |
| Evidence & replay | 1 | 0 | 0 | 1 | 0 | 25% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
sash.agent-identity |
Agent Identity Standard — every acting agent is a first-class, bound principal | designed | constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md |
sash.detection-triage |
Automated alert & triage — continuous posture signal on agent behaviour | advisory | constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.mdaudit_events: kye.agent.posture_signal.v1 |
sash.ace-exchange |
Agentic Cybersecurity Exchange (ACE) — independently verifiable evidence to share | advisory | constitution_refs: constitution/13-RESILIENCE-LOOP.mdaudit_events: kye.replay.proof.v1 |
sash.evidence-replay |
Post-incident reconstruction — replay-derivable record of the agent action | advisory | constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/21-DELEGATED-AUDITABILITY.mdaudit_events: kye.evidence.pack.v1, kye.replay.proof.v1 |