THREAT OPS › Threat News › Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers
<p>Developed by the National Institute of Standards and Technology (NIST) and CISA, this <a href="https://csrc.nist.gov/pubs/ir/8587/final" target="_blank">interagency report</a> provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt
Indicators of compromise
- https://csrc.nist.gov/pubs/ir/8587/finalurl
- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/finalurl
- https://www.congress.gov/crs_external_products/IN/HTML/IN12570.htmlurl