CISOOnline

AI agent authorization risks remain a gap in new NIST-CISA token security guidance

AI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans and AI agents alike.

“Protecting Tokens and Assertions from Forgery, Theft, and Misuse,” a new report from the National Institute of Standards and Technology (NIST) with help from the Cybersecurity and Infrastructure Security Agency (CISA), offers guidance for operators of systems that use digitally signed tokens to make access decisions, including single sign-on and API access.

The guidelines, also known as NIST IR 8587, address what happens after authentication: Tokens and assertions can carry proof of authentication or authorization between systems, allowing an attacker who compromises them to exploit access that has already been granted. NIST recommends continuous monitoring, along with tighter controls throughout the token lifecycle.



Source link