Securing the tool that secures: SISKO's internal Zero Trust
An obvious truth too often forgotten: the tool that protects an organisation becomes, if compromised, the attacker's best way in. SISKO's own security cannot be a side topic, it is the precondition for everything else.
First principle: no implicit trust, even inside. Every communication between components is encrypted and mutually authenticated (mTLS). No service trusts another by default, this is what we call internal Zero Trust.
Second principle: every command sent to an endpoint, block, isolate, kill a process, is cryptographically signed (Ed25519) and verified by the agent before execution. Injecting a fake command becomes impossible without the key.
Third principle: nothing is erased without a trace. Every sensitive action is written to an audit log where each line is linked to the previous one by a fingerprint (a Merkle-style chain) and signed. Any later tampering is immediately detectable.
Finally, the agent protects itself: signed binary, tamper detection, encrypted local buffer. Securing the tool that secures is not an option, it is the condition for deserving the trust placed in us.