New guidance for cloud identity infrastructure

CISA and NIST released final Interagency Report 8587 on September 15, addressing protection of identity tokens and assertions against theft, forgery and misuse. The agencies describe recommendations for federal agencies and cloud service providers, including token validation, key management and lifecycle controls. The report supports review of the mechanisms behind single sign-on, federation and API access. It is not an announcement that a particular cloud application has been breached.

A login is the start of a chain

CISA says the final report incorporates feedback from nearly 250 public comments and industry collaboration. Its significance for buyers is the opportunity to ask a more complete question about access. Our analysis is that an organization should be able to identify both the service that issues a token and the applications that accept it. A review that stops at the sign-in screen may leave nobody accountable for what happens when access must be withdrawn or a trust configuration changes.

Different organizations, the same ownership question

A government or defense contractor should establish which obligations actually apply to its environment rather than infer compliance from a product label. A professional-services firm can use the guidance as a basis for a technical discussion with its identity provider and MSP. In either case, we suggest beginning with one important client-facing application. Identify its owner, its authentication dependencies and the people responsible for investigating suspicious access. The exercise should produce a service map and an escalation path, not just a list of security features.

Ask for a demonstrable revocation process

For procurement and operational reviews, request an explanation of how compromised sessions and credentials are handled, what evidence is available and who can initiate the response. Any test should be planned with the provider using a non-production account or an approved maintenance window. Record the difference between changing a user’s password and terminating the access that a service currently recognizes. That distinction is the practical value of looking beyond the login: security teams need to know what their response actually stops.

Sources & further reading

Our practical suggestions are editorial guidance. Verify applicability against current source and vendor instructions.

Suggest a correction →