THE CRUNCH

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have released Interagency Report (IR) 8587. The guidance outlines how federal agencies and cloud service providers can defend identity tokens and assertions used in single sign-on, federation, and API access. The report advises on hardening token issuance, verification, and life cycle controls to,

The document expands on NIST Special Publication 800-53 and its IA-13 control. It provides architectural considerations for identity providers and enhancements to key management. CISA says the recommendations apply across commercial and government-operated cloud services and support the implementation of Executive Order 14306 on secure software development practices.

The final report incorporates feedback from nearly 250 public comments and reflects input from CISA’s collaboration with industry partners. Dozens of meetings were held with cloud providers, including Amazon Web Services, Google, Microsoft, and Okta. CISA Acting Executive Assistant Director for Cybersecurity Chris Butera said the guidelines give agencies a clear path to harden identity infrastructure.

WHAT HAPPENS NEXT

CISA urges federal agencies, CSPs and cloud consumers to review and implement IR 8587 to improve the security of their cloud systems.