Back to Feed
PolicySep 15, 2026

Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

NIST and CISA release updated guidance for agencies and cloud providers on protecting tokens and assertions.

Summary

NIST and CISA have published an interagency report offering guidelines for federal agencies and cloud service providers to safeguard identity assertions and access tokens. The report addresses the growing reliance on these mechanisms in hybrid and multi-cloud environments, where adversaries may target them for theft or forgery to facilitate lateral movement and data access. This final version incorporates feedback on token validation, secrets management, and detection, building upon existing NIST publications and supporting secure software development practices.

Full text

EXTERNAL, PUBLICATION Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers Publish DateSeptember 15, 2026 Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementatio… Related topics: Cybersecurity Best Practices , Critical Infrastructure Security and Resilience Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and assertions that adversaries may target for forgery, theft, and misuse to move laterally across enterprise networks and access sensitive data. This final report updates the initial public draft and incorporates feedback on token validation, secrets management, and detection at scale, as well as input from government and industry experts that CISA gathered through its Joint Cyber Defense Collaborative. The report expands on NIST Special Publication Security and Privacy Controls for Information Systems and Organizations and supports Executive Order 14306 on secure software development practices. It provides architectural considerations and emphasizes the importance of Secure by Design principles for interoperable defense across cloud environments. Tags Audience: Executives, Federal Government, Industry, Small and Medium Businesses, State, Local, Tribal, and Territorial Government Language: English Topics: Critical Infrastructure Security and Resilience, Cybersecurity Best Practices Related Resources Sep 02, 2026 Publication Communicating Under Pressure: Best Practices for Service Providers Aug 26, 2026 Publication CISA Vulnerability Review Jul 28, 2026 External CI Fortify – Advice for isolating vital systems Sep 03, 2026 External Preparing for the Post-Quantum Era: A Call to Action

Entities

NIST (vendor)CISA (vendor)API (technology)cloud (technology)