NIST Strengthens Safeguards For SSO And API Tokens Arabian Post
NIST Interagency Report 8587, released on September 15, sets out implementation recommendations for federal agencies and cloud service providers handling identity tokens, access tokens and assertions. The document focuses on how organisations should protect signing keys, verify tokens, manage their lifecycles and limit the damage if credentials are stolen or abused.
The guidance was developed with the Cybersecurity and Infrastructure Security Agency's Joint Cyber Defense Collaborative and supports Executive Order 14306. It builds on NIST Special Publication 800-53, the federal catalogue of security and privacy controls, while translating broader requirements into practical measures for identity providers, authorisation servers, cloud platforms and customers.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment