Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cloud

CISA, NIST Offer Guidelines to Help Agencies, CSPs Protect Identity Tokens

by Jane Edwards
September 16, 2026
in Cloud, Cybersecurity, DHS, News
Chris Butera. The CISA acting executive assistant director commented on new cloud identity token security guidelines.

Photo: Cybersecurity and Infrastructure Security Agency

  • CISA and NIST have issued guidance to help secure federal cloud identity systems against token theft
  • The report covers key management, token verification and identity provider architecture
  • DHS Deputy Secretary Troy Edgar will keynote the 2026 Homeland Security Summit on Nov. 10

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology have released an interagency report offering guidelines to help federal agencies and cloud service providers protect identity tokens and assertions that support single sign-on and application programming interface-based access from forgery and theft.

Table of Contents

    • You might also like
    • Coast Guard’s First MQ-9 Drones Take Shape as DHS Fleet Expands
    • Pentagon Memo Seeks to Eliminate Industrial Base Barriers
    • VA Seeks Health Systems Technology Integrator to Support Accountable Care Transition
  • What Does the Interagency Report Provide?
  • What Are the Report’s Key Recommendations?
  • How Does the Report Fit Into CISA’s Broader Cybersecurity Push?

You might also like

Coast Guard’s First MQ-9 Drones Take Shape as DHS Fleet Expands

Pentagon Memo Seeks to Eliminate Industrial Base Barriers

VA Seeks Health Systems Technology Integrator to Support Accountable Care Transition

2026 Homeland Security Summit tile ad. The Potomac Officers Club will host the event Nov. 10, featuring a keynote from DHS Deputy Secretary Troy Edgar.

As DHS continues to strengthen the security of federal networks and critical systems, the Potomac Officers Club will host the 2026 Homeland Security Summit on Nov. 10. DHS Deputy Secretary Troy Edgar will deliver a keynote address at the event, which will feature panel discussions on building the cyber workforce alongside fielding unmanned systems, coordination for counter-drone operations, AI and investigative intelligence, edge capabilities for borders and national events, and more. Save your spot now to join the conversation shaping the future of homeland security.

In a statement published Tuesday, Chris Butera, acting executive assistant director for cybersecurity at CISA, said identity has become the new perimeter and that the tokens supporting it are attractive targets for sophisticated adversaries.

“These guidelines give agencies and cloud providers a clear, practical path to harden token issuance, verification, and management so a stolen or forged credential can’t become a foothold across the federal enterprise,” Butera said. “I appreciate the expansive and insightful feedback and collaboration we received from the public and our industry and government partners. The insights not only informed this final report but also will support future CISA resources for addressing emerging cloud-related threats.”

What Does the Interagency Report Provide?

The report builds on Release 5.1.1 of NIST Special Publication 800-53 and the IA-13 control. According to CISA, the report provides:

  • Architectural considerations for identity providers and authorization servers
  • Enhancements to key management, token verification and token life cycle controls
  • Guidelines for securing single sign-on, federation and API access that rely on digitally signed, asymmetrically encrypted tokens
  • Principles for configurable, transparent and interoperable controls to support risk-informed, threat-adaptive defenses across cloud environments

CISA said the report reflects nearly 250 public comments on token validation, secrets management and detection at scale, along with input gathered through the Joint Cyber Defense Collaborative, including a June 2025 technical exchange with more than 50 industry experts and individual meetings with cloud service providers such as Google, HashiCorp, IBM, Microsoft, Okta, the OpenID Foundation, Oracle, Amazon Web Services and Wiz.

What Are the Report’s Key Recommendations?

The report lays out technical measures agencies and cloud service providers can adopt to secure token- and assertion-based access across their environments. Recommendations include:

  • Isolating cryptographic signing keys using hardware security modules, embedded processors or other protected storage mechanisms, with additional safeguards for systems categorized at a higher impact level
  • Limiting how long signing keys remain active, with the report pointing to periods of 90 days or less for higher-impact systems, paired with automated rotation processes to reduce manual error
  • Keeping access and identity tokens short-lived, generally no longer than one hour, to limit the window in which a stolen or forged credential could be used
  • Restricting tokens to their intended audience and scope so that a credential issued for one system or tenant cannot be applied elsewhere
  • Building in revocation and monitoring capabilities, including shared signal frameworks that let identity providers and connected applications flag compromised sessions in near real time
  • Applying added protections for machine and workload identities, such as short-lived, tightly scoped credentials rather than static, long-standing secrets
  • Maintaining detailed, tamper-resistant logs of token and assertion activity to support detection and incident response

The agencies said the recommendations apply across both commercial and government-operated cloud services. The guidance is also designed to support implementation of Executive Order 14306 on secure software development practices.

CISA is urging federal agencies, CSPs and cloud consumers to review and implement the report’s recommendations to strengthen the security of their cloud systems.

How Does the Report Fit Into CISA’s Broader Cybersecurity Push?

The latest interagency report from CISA and NIST builds on a series of recent agency actions aimed at strengthening federal and critical infrastructure cybersecurity. CISA has separately released a Logging Reference Architecture to help agencies standardize logging and network visibility practices, while a joint advisory with the FBI, National Security Agency and other partners detailed the tactics used by Gunra ransomware actors to compromise victim networks.

The agency has also worked with international partners to issue guidance on establishing coordinated vulnerability disclosure programs and launched a new nomination form for reporting known exploited vulnerabilities to speed up detection and response.

Beyond guidance, CISA introduced CI Fortify, an initiative that helps critical infrastructure operators isolate and recover systems during a cyberattack, and published findings from red team assessments of two critical infrastructure organizations to help other operators sharpen their detection capabilities.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

CISA Seeks CIO to Lead Cybersecurity, IT & Communications Operations

Next Post

OPM to Expand AI Use Following OneGov OpenAI Agreement

Recommended For You

Army Prepares for Rapid Fielding of Altius 700 Launched Effects Prototype

by Naomi Cooper
May 15, 2024
Altius 700 flight demonstration_272x270

U.S. Army officials are exploring rapid deployment approaches for a "launched effects" prototype based around the Air-Launched, Tube-Integrated Unmanned System 700, or Altius 700, design by Area-I, an...

Read moreDetails

Verizon-Lockheed Martin Partnership to Deliver 5G.MIL Technology for DOD Systems; Kyle Malady, Rod Makoske Quoted

by reynolitoresoor
November 3, 2021
Verizon-Lockheed Martin Partnership to Deliver 5G.MIL Technology for DOD Systems; Kyle Malady, Rod Makoske Quoted

Verizon has signed an agreement with Lockheed Martin to collaborate on delivering 5G.MIL technologies for the Department of Defense in support of its JADC2 initiative. As part of the...

Read moreDetails

DOD Approves Private 5G Network Deployment Strategy

by Jerry Petersen
November 13, 2024
DOD Approves Private 5G Network Deployment Strategy

The Department of Defense has signed a strategy covering the deployment of private 5G networks at military installations. Private 5G is expected to augment or supplement commercial 5G,...

Read moreDetails

Savannah River National Lab Unveils Regulatory Center of Excellence; Connie Herman Quoted

by Jane Edwards
June 2, 2022
Savannah River National Lab Unveils Regulatory Center of Excellence; Connie Herman Quoted

Savannah River National Laboratory has formed a new center of excellence to help Department of Energy sites address regulatory and stakeholder challenges, advance cleanup and reduce liability and...

Read moreDetails

Maxar Technologies, Australian Space Agency Sign Cooperative Agreement; Dan Jablonsky Quoted

by William McCormick
October 23, 2019
Maxar Technologies, Australian Space Agency Sign Cooperative Agreement; Dan Jablonsky Quoted

Maxar Technologies has signed a joint statement of strategic intent and cooperation with the Australian Space Agency, Maxar announced on Wednesday. 

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Emerging Tech
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!