CISA & NIST release IR 8587 with implementation guidance for federal agencies and CSPs to defend identity tokens and assertions against theft, forgery, and misuse
CISA and NIST published Interagency Report (IR) 8587, providing concrete implementation recommendations for protecting identity tokens and assertions used in SSO, federation, and API-based access across federal cloud environments. The guidance targets adversarial techniques — such as lateral movement via stolen or forged credentials — that increasingly exploit identity infrastructure as the primary attack vector. Federal agencies and CSPs are urged to review and implement IR 8587 to meet existing NIST SP 800-53 controls (including IA-13) and align with Executive Order 14306. Compliance teams should assess whether their token issuance, verification, lifecycle management, and key management practices meet the architectural and operational baselines established in the report.
What changed
- New guidance document issued: NIST IR 8587 provides implementation recommendations for securing identity tokens and assertions against forgery, theft, and misuse in federal cloud environments.
- Expanded coverage of NIST SP 800-53 Release 5.1.1 and the IA-13 control, with architectural guidance for identity providers and authorization servers.
- Specific technical controls added for key management, token verification, and token lifecycle management, including for digitally signed and asymmetrically encrypted tokens used in SSO, federation, and API access.
- Principles for configurable, transparent, and interoperable controls to support risk-informed, threat-adaptive defenses across both commercial and government-operated cloud services.
- Implementation of IR 8587 linked to compliance with Executive Order 14306 on secure software development practices.
Who is affected
U.S. federal agencies and cloud service providers (CSPs) operating or consuming commercial or government cloud services; relevant to cybersecurity, identity, and compliance teams within those organizations.
- Effective
- 2026-09-15
- Action
- Action required
- Language
- EN