Tuesday, 02 January 2024 12:17 GMT

NIST Strengthens Safeguards For SSO And API Tokens Arabian Post


(MENAFN- The Arabian Post) clearfix">The US National Institute of Standards and Technology has finalised new guidance aimed at reducing theft, forgery and misuse of digital tokens that underpin single sign-on, cloud federation and API access.

NIST Interagency Report 8587, released on September 15, sets out implementation recommendations for federal agencies and cloud service providers handling identity tokens, access tokens and assertions. The document focuses on how organisations should protect signing keys, verify tokens, manage their lifecycles and limit the damage if credentials are stolen or abused.

The guidance was developed with the Cybersecurity and Infrastructure Security Agency's Joint Cyber Defense Collaborative and supports Executive Order 14306. It builds on NIST Special Publication 800-53, the federal catalogue of security and privacy controls, while translating broader requirements into practical measures for identity providers, authorisation servers, cloud platforms and customers.

MENAFN16092026000152002308ID1111675287



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story