NIST and CISA Finalize Interagency Report on Protecting Tokens and Assertions from Forgery Theft and Misuse

09/15/2026 11:15 AM EST

Banner image for the Cybersecurity and Infrastructure Security Agency (CISA) featuring a globe and digital graphics.

Today, the Cybersecurity and Infrastructure Security Agency (CISA) and National Institute of Standards and Technology (NIST) released the final version of Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers (CSPs) to help federal agencies and CSPs safeguard the identity tokens and assertions that underpin modern single sign-on (SSO), federation, and application programming interface (API)-based access—systems that cyber threat actors are increasingly targeting to move laterally through enterprise networks and reach sensitive data.

This report expands on NIST’s Special Publication 800-53 (revision 5) Security and Privacy Controls for Information Systems and Organizations, supports Executive Order 14306, and incorporates feedback from a public comment period and webinar, along with input from CISA’s ongoing work with CSPs and experts across government and industry through the Joint Cyber Defense Collaborative. It also addresses recent high-profile attacks, emphasizes the importance of secure and configurable cloud services, and provides technical recommendations, including:

  • Architectural considerations for identity providers and authorization servers;
  • Enhancements to key management, token verification, and token lifecycle controls;
  • Guidelines for securing SSO, federation, and API access relying on digitally signed, asymmetrically encrypted tokens; and
  • Principles for configurable, transparent, and interoperable controls supporting risk-informed, threat-adaptive defenses across cloud environments.

The recommendations in this report apply to both commercial and government-operated cloud services. CISA encourages all organizations and CSPs to review the full report and begin implementation. CISA also urges CSPs and cloud consumers to consider adopting the guidelines outlined in IR 8587 to improve the security of their cloud systems.


Discover more from #News247WorldPress

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading