Singapore SASH — Detecting Offensive Cyber Agents (Defence-in-Depth) · v2026 (SASH)

Singapore SASH — Detecting Offensive Cyber Agents (Defence-in-Depth)

Singapore SASH — Detecting Offensive Cyber Agents (Defence-in-Depth) — 31% of in-scope requirements covered.

4 requirements · 4 in scope (1 designed · 3 advisory). The 31% is weighted over the in-scope base.

Source: Singapore SASH (Security Alert Standard / Honeypots) — 'Detecting Offensive Cyber Agents' defence-in-depth framework (2026): agent identity mechanisms, agent honeypots, automated alert/triage, a security alert standard, and the Agentic Cybersecurity Exchange (ACE). KYE Protocol governs the AUTHORITY, IDENTITY and EVIDENCE of agent actions — it makes a defending organisation's own agents first-class, identifiable principals whose actions are replay-provable, complementing detection-in-depth. KYE is not an intrusion-detection / honeypot product; it is the authority + evidence substrate the identity and alert layers assume. Starter requirement set; deepen by graft through the §70 rail. · License: SASH materials are Singapore-government publications; KYE registry paraphrases each mechanism's intent and cites the mechanism identifier for mapping purposes only.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Agent identity 1 0 1 0 0 50%
Detection & triage 1 0 0 1 0 25%
Alert standard & exchange 1 0 0 1 0 25%
Evidence & replay 1 0 0 1 0 25%

Every requirement → the KYE artefact that enforces it

IDTitleStatusKYE enforcement
sash.agent-identity Agent Identity Standard — every acting agent is a first-class, bound principal designed constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md
sash.detection-triage Automated alert & triage — continuous posture signal on agent behaviour advisory constitution_refs: constitution/52-DELEGATED-AGENT-BINDING.md
audit_events: kye.agent.posture_signal.v1
sash.ace-exchange Agentic Cybersecurity Exchange (ACE) — independently verifiable evidence to share advisory constitution_refs: constitution/13-RESILIENCE-LOOP.md
audit_events: kye.replay.proof.v1
sash.evidence-replay Post-incident reconstruction — replay-derivable record of the agent action advisory constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/21-DELEGATED-AUDITABILITY.md
audit_events: kye.evidence.pack.v1, kye.replay.proof.v1