Appearance
Security reviewers & program managers · Zero Trust mapping · how we work together
NIST SP 800-207 tenets → POC evidence
| # | Tenet | What the POC shows |
|---|---|---|
| 1 | Secured communications | Access / service tokens; edge without public IPs; mTLS where configured |
| 2 | Least privilege | Allowlisted operators; admin surfaces separated from read paths |
| 3 | Per-request authorization | Sensitive actions re-validated; activity logging on app surfaces |
| 4 | Dynamic policy | Live status and degraded modes if control plane is unreachable |
| 5 | Data / control plane split | Bulk video stays edge-local; MQTT + justified clips to host |
| 6 | Monitoring | Proxy health, MQTT telemetry, operator audit trails |
| 7 | Resilience | Offline / emergency operator paths when primary path fails |
Broader AI RMF: NIST AI RMF compliance.
How we engage
Working agreements
- One technical channel after kickoff (Slack/Teams shared).
- Escalate Access / security issues via Ghost Protocol POC contacts (
info@ghostprotocol.usfor routing). - Never paste HMAC, device passwords, or private keys into chat—docs hub + private handoff only.
- OTA and model pulls are deliberate—written window; see host updates cadence.