Critical New document us

CISA & NIST release IR 8587 with implementation guidance for federal agencies and CSPs to defend identity tokens and assertions against theft, forgery, and misuse

CISA and NIST published Interagency Report (IR) 8587, providing concrete implementation recommendations for protecting identity tokens and assertions used in SSO, federation, and API-based access across federal cloud environments. The guidance targets adversarial techniques — such as lateral movement via stolen or forged credentials — that increasingly exploit identity infrastructure as the primary attack vector. Federal agencies and CSPs are urged to review and implement IR 8587 to meet existing NIST SP 800-53 controls (including IA-13) and align with Executive Order 14306. Compliance teams should assess whether their token issuance, verification, lifecycle management, and key management practices meet the architectural and operational baselines established in the report.

What changed

Who is affected

U.S. federal agencies and cloud service providers (CSPs) operating or consuming commercial or government cloud services; relevant to cybersecurity, identity, and compliance teams within those organizations.

Effective
2026-09-15
Action
Action required
Language
EN

Frameworks

CISA NIST SP 800-53

Open the original source