CISA and NIST Release Guidelines to Protect Federal Cloud Identity Systems from Token Theft, Forgery, and Misuse
WASHINGTON –The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) today released Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers (CSPs). The report guides federal agencies and CSPs in defending the identity tokens and assertions that underpin modern single sign-on (SSO), federation, and application programming interface (API)-based access, systems adversaries increasingly target to move laterally through enterprise networks and reach sensitive data.
The final report incorporates key feedback from nearly 250 public comments on token validation, secrets management, and detection at scale. The report also reflects input from CISA’s long-term, strategic collaboration with industry CSPs and interagency partners through the Joint Cyber Defense Collaborative. CISA and NIST engagements with this group included a technical exchange in June 2025 with over 50 industry experts to identify approaches to harden identity infrastructure and a webinar in January 2026 to review the draft report. Dozens of individual meetings with CSPs were also held to discuss feedback that included Google, HashiCorp, an IBM Company, IBM, Microsoft Corporation, Okta Inc., the OpenID Foundation, Oracle America, Inc., Amazon Web Services, and Wiz.
“Identity is the new perimeter, and the tokens and assertions behind it are attractive targets for sophisticated adversaries. These guidelines give agencies and cloud providers a clear, practical path to harden token issuance, verification, and management so a stolen or forged credential can’t become a foothold across the federal enterprise,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “I appreciate the expansive and insightful feedback and collaboration we received from the public and our industry and government partners. The insights not only informed this final report but also will support future CISA resources for addressing emerging cloud-related threats.”
The final report expands on Release 5.1.1 of NIST Special Publication (SP) 800-53 and SP 800-53’s IA-13 control, and provides:
- Architectural considerations for identity providers and authorization servers;
- Enhancements to key management, token verification, and token life cycle controls;
- Guidelines for securing SSO, federation, and API access relying on digitally signed, asymmetrically encrypted tokens; and
- Principles for configurable, transparent, interoperable controls supporting risk-informed, threat-adaptive defenses across cloud environments.
The recommendations in the final report apply across commercial and government-operated cloud services and support implementation of Executive Order 14306 on secure software development practices.
CISA urges federal agencies, CSPs and cloud consumers to review and implement IR 8587 to improve the security of their cloud systems.
For more information on this effort, read NIST’s News Release.
###
Disclaimer
CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services referenced or linked to on this page. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA. Full Disclaimer: See https://www.cisa.gov/notification.
About CISA
As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.
Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.
Fuente:
Leer la noticia original