CISA and NIST Release Identity Token Security Guidance Citing Federal Agency Email Breach
CISA and NIST published final NIST Interagency Report 8587 on September 15, providing federal agencies and cloud service providers with implementation guidance to protect identity tokens and
NIST IR 8587 turns a discretionary identity-token control into a measurable compliance baseline, requiring documented key inventories, 90-day active-period caps on high-impact signing keys, and logging pipelines rebuilt around token activity rather than credential events alone. CISA and NIST now treat forged-assertion attacks, not just credential theft, as the primary vector for lateral movement into federal systems. Sourcing traces to a single primary document, the interagency report itself, with outlets offering amplification rather than independent verification. The Storm-0558 breach citation may function as retrospective justification for a report already in motion under Executive Order 14306 rather than evidence the incident shaped its specific technical requirements. Conformance stays voluntary absent OMB or contract mandates, and the guidance's extension into agentic AI token flows and post-quantum key sizing burdens systems most agencies have not yet inventoried.
3 sources
- Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers -
CISA - CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse -
Cybersecurity News - NIST and CISA Release Guidelines on Protecting Digital Access Tokens -
SSBCrack News