NIST, CISA issue guidelines on protecting authentication tools from forgery, theft
The National Institute of Standards and Technology and the Cybersecurity and Infrastructure and Security Agency have released guidelines to protect authentication tools including access tokens and identity assertions from cyber criminals. Services such as single sign-on, which are extensively used in hospitals and health systems, increasingly rely on signed tokens and identity assertions and could be targeted by cyber actors to conduct forgery, theft and misuse and access sensitive data. The report includes technical recommendations for protection and addresses threats from recent high-profile cyber incidents. The agencies also reinforce the need for having secure-by-design practices, configurability, interoperability and continuous monitoring.
For more information on this and other cyber and risk issues, contact John Riggi, AHA national advisor for cybersecurity and risk, at jriggi@aha.org, or Scott Gee, AHA deputy national advisor for cybersecurity and risk, at sgee@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.