- CISA and NIST have issued guidance to help secure federal cloud identity systems against token theft
- The report covers key management, token verification and identity provider architecture
- DHS Deputy Secretary Troy Edgar will keynote the 2026 Homeland Security Summit on Nov. 10
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology have released an interagency report offering guidelines to help federal agencies and cloud service providers protect identity tokens and assertions that support single sign-on and application programming interface-based access from forgery and theft.

As DHS continues to strengthen the security of federal networks and critical systems, the Potomac Officers Club will host the 2026 Homeland Security Summit on Nov. 10. DHS Deputy Secretary Troy Edgar will deliver a keynote address at the event, which will feature panel discussions on building the cyber workforce alongside fielding unmanned systems, coordination for counter-drone operations, AI and investigative intelligence, edge capabilities for borders and national events, and more. Save your spot now to join the conversation shaping the future of homeland security.
In a statement published Tuesday, Chris Butera, acting executive assistant director for cybersecurity at CISA, said identity has become the new perimeter and that the tokens supporting it are attractive targets for sophisticated adversaries.
“These guidelines give agencies and cloud providers a clear, practical path to harden token issuance, verification, and management so a stolen or forged credential can’t become a foothold across the federal enterprise,” Butera said. “I appreciate the expansive and insightful feedback and collaboration we received from the public and our industry and government partners. The insights not only informed this final report but also will support future CISA resources for addressing emerging cloud-related threats.”
What Does the Interagency Report Provide?
The report builds on Release 5.1.1 of NIST Special Publication 800-53 and the IA-13 control. According to CISA, the report provides:
- Architectural considerations for identity providers and authorization servers
- Enhancements to key management, token verification and token life cycle controls
- Guidelines for securing single sign-on, federation and API access that rely on digitally signed, asymmetrically encrypted tokens
- Principles for configurable, transparent and interoperable controls to support risk-informed, threat-adaptive defenses across cloud environments
CISA said the report reflects nearly 250 public comments on token validation, secrets management and detection at scale, along with input gathered through the Joint Cyber Defense Collaborative, including a June 2025 technical exchange with more than 50 industry experts and individual meetings with cloud service providers such as Google, HashiCorp, IBM, Microsoft, Okta, the OpenID Foundation, Oracle, Amazon Web Services and Wiz.
What Are the Report’s Key Recommendations?
The report lays out technical measures agencies and cloud service providers can adopt to secure token- and assertion-based access across their environments. Recommendations include:
- Isolating cryptographic signing keys using hardware security modules, embedded processors or other protected storage mechanisms, with additional safeguards for systems categorized at a higher impact level
- Limiting how long signing keys remain active, with the report pointing to periods of 90 days or less for higher-impact systems, paired with automated rotation processes to reduce manual error
- Keeping access and identity tokens short-lived, generally no longer than one hour, to limit the window in which a stolen or forged credential could be used
- Restricting tokens to their intended audience and scope so that a credential issued for one system or tenant cannot be applied elsewhere
- Building in revocation and monitoring capabilities, including shared signal frameworks that let identity providers and connected applications flag compromised sessions in near real time
- Applying added protections for machine and workload identities, such as short-lived, tightly scoped credentials rather than static, long-standing secrets
- Maintaining detailed, tamper-resistant logs of token and assertion activity to support detection and incident response
The agencies said the recommendations apply across both commercial and government-operated cloud services. The guidance is also designed to support implementation of Executive Order 14306 on secure software development practices.
CISA is urging federal agencies, CSPs and cloud consumers to review and implement the report’s recommendations to strengthen the security of their cloud systems.
How Does the Report Fit Into CISA’s Broader Cybersecurity Push?
The latest interagency report from CISA and NIST builds on a series of recent agency actions aimed at strengthening federal and critical infrastructure cybersecurity. CISA has separately released a Logging Reference Architecture to help agencies standardize logging and network visibility practices, while a joint advisory with the FBI, National Security Agency and other partners detailed the tactics used by Gunra ransomware actors to compromise victim networks.
The agency has also worked with international partners to issue guidance on establishing coordinated vulnerability disclosure programs and launched a new nomination form for reporting known exploited vulnerabilities to speed up detection and response.
Beyond guidance, CISA introduced CI Fortify, an initiative that helps critical infrastructure operators isolate and recover systems during a cyberattack, and published findings from red team assessments of two critical infrastructure organizations to help other operators sharpen their detection capabilities.





