Medium New document us

CISA and NIST release guidelines to protect federal cloud identity systems from token theft, forgery, and misuse

Original title: CISA and NIST Release Guidelines to Protect Federal Cloud Identity Systems from Token Theft, Forgery, and Misuse

CISA and NIST released Interagency Report (IR) 8587 providing comprehensive guidelines for federal agencies and cloud service providers to defend identity tokens and assertions used in single sign-on, federation, and API-based access systems. The report incorporates feedback from nearly 250 public comments and collaboration with over 50 industry experts, addressing token validation, secrets management, and detection at scale. Federal agencies and cloud service providers must review and implement these guidelines to harden token issuance, verification, and management, preventing stolen or forged credentials from becoming entry points for lateral movement across enterprise networks.

What changed

  • CISA and NIST published IR 8587 with architectural considerations for identity providers and authorization servers to strengthen cloud identity infrastructure security.
  • Enhanced guidance on key management, token verification, and token lifecycle controls to prevent token theft and forgery attacks.
  • New guidelines for securing single sign-on (SSO), federation, and API access relying on digitally signed, asymmetrically encrypted tokens.
  • Principles for implementing configurable, transparent, and interoperable controls that support risk-informed, threat-adaptive defenses across cloud environments.
  • Expansion of NIST SP 800-53 Release 5.1.1, particularly IA-13 control, with practical recommendations for federal agencies and cloud service providers.

Who is affected

Federal agencies, cloud service providers (CSPs), and cloud consumers operating in the United States. Applies across commercial and government-operated cloud services.

Action
Action required
Language
EN

Frameworks

CISA NIST SP 800-53

Open the original source