Security Program Controls/Technologies, Identity, IAM Technologies, Cloud Security, Government Regulations

CISA, NIST issue new guidance to stop cloud identity token theft

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have released final guidance for federal agencies and cloud service providers on how to protect cloud identity tokens and assertions from theft, forgery, and misuse, according to a recent report by Infosecurity Magazine.

Interagency Report 8587, published September 15, addresses the critical tokens used for single sign-on, identity federation, and API access, which are increasingly targeted by adversaries for lateral movement and data exfiltration. The guidance, which is voluntary, recommends that access and identity tokens be valid for no more than one hour and that expired tokens be rejected. Key management practices include rotating signing keys for high-impact systems at least every 90 days and within a year for others. These keys must be stored in hardware-backed or isolated storage, never persistently on the servers using them. Tokens must have an explicit audience field and personal data within them should never be logged. The report also notes the increasing use of tokens by AI agents, stating the guidance applies to these scenarios as well. This guidance was developed following two significant token compromise incidents in 2020 and later, which led to unauthorized access and data theft within federal agencies and other organizations.

Source: Infosecurity Magazine

You can skip this ad in 5 seconds