Written for federal agencies and cloud service providers, NIST’s guidelines can help any organisation handling identity tokens and assertions than undermine single-sign on authentication. These tokens can be attractive to bad actors. NIST finalises in its Interagency Report 8587 the approach CSPs should take to bolstering token verification and critical lifecycle controls to protect against adversaries.

Over 20 contributors have left comments on the draft to enhance sections about signing key protections and the distinction between secure storage guidelines and secure usage of keys.

CISA Acting Executive Assistant Director for Cybersecurity Chris Butera:

“Identity is the new perimeter, and the tokens and assertions behind it are attractive targets for sophisticated adversaries. These guidelines give agencies and cloud providers a clear, practical path to harden token issuance, verification, and management so a stolen or forged credential can’t become a foothold across the federal enterprise”.

Tokens often lies behind a sign in process to an online platform which encompasses information about a person’s identity and what access permissions they have to online resources and sensitive data. Moreover, they are a key part of the access management infrastructure at most CSPs and cryptographically hold information securely whilst create the ease of single-sign on as part of the authentication process.