< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

CISA and NIST issue new cloud identity token security guidelines

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have released Interagency Report 8587, titled ‘Protecting Tokens and Assertions from Forgery, Theft, and Misuse’. The report provides security guidelines for federal agencies and cloud service providers to defend identity infrastructure against sophisticated attacks targeting identity tokens and assertions used in single sign-on and API-based access.

The guidance aims to harden token issuance, verification, and management to prevent stolen or forged credentials from providing access to federal enterprises. The OpenID Foundation participated in the development of the report, which specifically recommends implementing the Shared Signals Framework (SSF) and the Continuous Access Evaluation Profile (CAEP). These specifications allow identity providers and relying parties to exchange security signals and continuously re-evaluate user access based on changes in session risk.

Entities

CISA · Department of Homeland Security · NIST · OpenID Foundation