Security / WORLD

NIST and CISA finalize guidance on protecting access tokens

NIST IR 8587 sets out implementation recommendations for federal agencies and cloud providers managing identity tokens.

Reading sizeSources ↓Share story ↗

The National Institute of Standards and Technology and the US Cybersecurity and Infrastructure Security Agency published the final NIST IR 8587 on 15 September 2026. The guidance gives federal agencies and cloud service providers implementation recommendations for protecting identity and access tokens against forgery, theft and misuse.

It addresses identity-provider and authorization-server architecture, key management, token verification and lifecycle controls. NIST says the report covers single sign-on, federation and API access scenarios and was revised after public feedback on its draft.

Data

Timeline

Security development

Information and scope published by the source.

  1. · Occurred

    NIST IR 8587 published

    NIST and CISA published final implementation guidance on protecting identity and access tokens from forgery, theft and misuse.

Methodology

Figures and dates are reproduced as stated by the source; no additional forecast is made.

Updated:

Structured coverage

Subjects and places

Subject proposals

Taxonomy version: IPTC Media Topics 2026-Q2

Continue reading

Security

British Army completes trial of an eight-drone swarm test bed

Eight weeks of experimentation with a Dstl-developed test bed assessed how uncrewed aircraft under collective control could perform field tasks.

Defence Science and Technology Laboratory (Dstl), UK Ministry of Defence1 min read
Data included