CISA and NIST Issue New Guidance to Combat Cloud Identity Token Theft
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have jointly released final guidance aimed at protecting cloud identity tokens and assertions from theft, forgery, and misuse. This guidance, detailed in Interagency Report 8587 published on September 15, addresses critical tokens used for single sign-on, identity federation, and API access, which are increasingly targeted by adversaries for unauthorized access and data exfiltration. The recommendations, though voluntary, suggest that access and identity tokens should be valid for a maximum of one hour, and expired tokens must be rejected. Key management practices include rotating signing keys for high-impact systems at least every 90 days and annually for others. These keys are mandated to be stored in hardware-backed or isolated storage, never persistently on the servers utilizing them. Additionally, tokens must include an explicit audience field, and personal data within them should ...