Embracing zero-trust: a look at the NSAs recommended IAM best practices for administrators – CSO Online
By now, most of the industry has realized were seeing a shift from the legacy perimeter-based security model to an identity-centric approach to cybersecurity. If defenders havent realized this, malicious actors certainly have, with 80% of web application attacks utilizing stolen credentials and 40% of breaches that dont involve insider threats and user error involving stolen credentials, according to sources such as the 2022 Verizon Data Breach Investigation Report.
Compromised credentials were involved in incidents such as the 2021 Colonial national gas pipeline breach, the 2021 Oldsmar Florida water treatment plant attack, and an attack on the South Staffordshire water treatment plant in the UK in 2022, illustrating that these incidents can and have spilled over from the digital realm to the physical, impacting critical infrastructure.
Luckily, were seeing a change in the industry to pivot to a zero-trust model of cybersecurity, underpinned by an emphasis on identity and data rather than the legacy castle-and-moat approach that preceded it and led to several decades of brittle defense and massive data breaches. This pivot includes guidance from leading organizations such as the National Security Agency (NSA), which in conjunction with the Cybersecurity and Infrastructure Security Agency (CISA) recently released a Recommended Best Practices for Administrations - Identity and Access Management (IAM) guide.
The guidance opens by discussing the current threat landscape along with an overview of threat mitigation techniques. The NSA points out that some of the most common techniques used by malicious actors include activities such as creating new accounts to maintain persistence, exploiting vulnerabilities to forge authentication assertions, exploiting existing users and their access, and exploiting insecure system defaults and configurations. The guides most salient sections are dedicated to identity governance, environmental hardening, identity federation and single sign-on (SSO), multifactor authentication (MFA), and auditing and monitoring, which we will discuss below.
Identity governance helps organizations centralize and orchestrate activities associated with both user- and non-person entities (NPE) such as service accounts to align with their organizational policies. These activities cover the entire lifecycle of an account or identity, such as when an individual joins, moves, or leaves an organization or a team, triggering activities associated with their credentials and associated permissions. That same concept applies to NPEs such as machine-based identities that need credentials and permissions to carry out activities within an architecture.
Determining who has access to what and the risks associated with that access and then dynamically managing the access appropriately is no easy task. Identity governance enables a centralized approach to ensure the broad application of organizational policies, as well as mitigating risks such as identity sprawl and permission creep, in which individuals accounts are properly managed but their associated permissions regularly extended beyond what they actually need for their jobs. When this occurs and those credentials are compromised or abused, it can wreak havoc on organizations.
Leveraging innovative and emerging technologies, organizations can enable this governance while also taking advantage of capabilities such as conditional-based access control and dynamic least-permissive access control rather than long-lived credentials and access. Implementing identity governance can help mitigate attacks such as phishing, insider threats, and malicious actors creating accounts to maintain persistence beyond their initially compromised account. The NSA guidance also recommends utilizing privileged access management (PAM) solutions for advanced capabilities such as just-in-time access control.
Identity governance utilizes hardware, software, and digital environments to enable its implementation, and this is where environmental hardening comes into play. The NSA guidance points out that environmental hardening activities such as patching, asset management, and networking segmentation, along with other security best practices are key to mitigating the potential for compromised credentials, as well as limiting the blast radius, should an incident occur.
It is well known that malicious actors regularly try to compromise IAM components, so ensuring the security of environments in which those components operate is a key consideration. This includes performing activities such as creating a comprehensive asset inventory, understanding the connectivity of the assets youve identified, and protecting assets appropriately based on how critical they are to a business. You dont apply the same level of resources and rigor to a publicly available, non-sensitive system as you do to your crown jewel systems, for example.
Knowing that credentials are a key target for malicious actors, utilizing techniques such as identity federation and single sign-on can mitigate the potential for identity sprawl, local accounts, and a lack of identity governance. This may involve extending SSO across internal systems and also externally to other systems and business partners.
SSO also brings the benefit of reducing the cognitive load and burden on users by allowing them to use a single set of credentials across systems in the enterprise, rather than needing to create and remember disparate credentials. Failing to implement identity federation and SSO inevitably leads to credential sprawl with disparate local credentials that generally arent maintained or governed and represent ripe targets for bad actors.
SSO is generally facilitated by protocols such as SAML or Open ID Connect (OIDC). These protocols help exchange authentication and authorization data between entities such as Identity Providers (IdP)s and service providers. It is key for organizations utilizing SSO to understand the protocols involved as well as how the service providers involved have secured the protocols and the services themselves. The guidance provides a logical depiction of an example authorization data flow.
Best practices for implementing identity federation and SSO include knowing what systems in the environment are integrated with SSO or utilizing local identities, understanding how your trusted partners may leverage local accounts, and utilizing configuration management solutions to support identifying, tracking, and reporting on local account usage in an environment while working to get more systems federated and integrated with SSO to cut down on local account usage and its associated risks.
By now, most CISOs should be familiar with MFA. But for those who arent, at a high level, MFA requires users to utilize multiple factors as part of their authentication activities. Think of a username and password plus an SMS text or code sent to an authentication app on your phone. As shown in the NSA guidance, these factors typically take the form of using something you have, know, or are (such as biometrics) as validation tools.
We know that malicious actors are after credentials to carry out their activities and the use of MFA significantly decreases the risk of compromised credentials, particularly high-assurance approaches such as phishing-resistant MFA.
MFA helps mitigate situations in which passwords have been exposed through external system compromises or by unauthorized users who convince victims to share their passwords. The use of strong MFA form factors ensures that the exposure of a username and password alone wont leave an account compromised. The NSA guidance ranks MFA types, from weakest to strongest as SMS or voice, app-based MFA, and phishing-resistant MFA such as PKI-based systems and fast-identity hardware tokens (FIDO).
It is often said that many organizations are already compromised they just dont know it yet. This is where activities such as identity access management auditing and monitoring come into play, with value beyond compliance purposes: it helps identify anomalous or malicious activity present in an environment.
IAM auditing can provide insight into how systems are being used or abused, detect problems earlier in their lifecycle, aid in gathering forensic evidence which may be needed later as well as ensure privileged users know their activities are being monitored.
To prepare to implement successful and effective IAM auditing and monitoring, organizations need to first understand what normal behavior is, be familiar with organizationally defined policies and processes, as well as identify users with access to critical assets so they know what users and activities are the most critical to audit and monitor.
Organizations also need to ensure they have sufficient tooling and analytical capabilities in place to make use of the collected data and telemetry, as well as ensuring they have tooling in place to gather and consolidate it, to begin with. Organizations will also want to ensure they are not collecting noise and irrelevant data that simply distract from signals that are of real concern and pose risks to the organization.
Organizations looking to implement NSA-recommended identity and access management (IAM) protocols, the agency provides an appendix in the guidance that provides a detailed checklist for each of the areas discussed throughout this article. This provides a quick punch list approach to allow organizations to tackle the most pressing and key activities when it comes to securing their IAM processes and systems.
See the original post:
Embracing zero-trust: a look at the NSAs recommended IAM best practices for administrators - CSO Online
- Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI - The Record from Recorded Future News - September 15th, 2026 [September 15th, 2026]
- United States NSA recruits psychologists in bid to boost its appeal to new blood - Intelligence Online - September 15th, 2026 [September 15th, 2026]
- NSA releases best practices guide on cyber hygiene for defending against advanced threats - American Hospital Association - September 15th, 2026 [September 15th, 2026]
- United States NSA recruits psychologists in bid to boost its appeal to new blood - Intelligence Online - September 15th, 2026 [September 15th, 2026]
- NSA, FBI & CISA Issue Advisory on China-Based AI Distillation Campaigns - ExecutiveGov - September 15th, 2026 [September 15th, 2026]
- NSA, FBI & CISA Issue Advisory on China-Based AI Distillation Campaigns - ExecutiveGov - September 15th, 2026 [September 15th, 2026]
- NSA set to get five new organizations - Breakingthenews.net - September 15th, 2026 [September 15th, 2026]
- FBI, NSA warn Chinese AI companies like DeepSeek and Alibaba are reportedly carrying out 'industrial-scale' distillation campaigns to boost their... - September 15th, 2026 [September 15th, 2026]
- Confused about which VPN is right, US senator asks the NSA for guidance - Ars Technica - September 4th, 2026 [September 4th, 2026]
- Former NSA cybersecurity official: Pro-China 'influence operations' and 'cognitive warfare' work in protests against data centers and Flock cameras -... - September 4th, 2026 [September 4th, 2026]
- Can the county home to the NSA and US Cyber Command ban data centers? - The Baltimore Banner - September 4th, 2026 [September 4th, 2026]
- Family proud of her work for poor: DU students father after HC quashes NSA case - The Times of India - September 4th, 2026 [September 4th, 2026]
- Man who cut down Flock camera in St. Johns County claimed he was working with the NSA - Action News Jax - September 4th, 2026 [September 4th, 2026]
- Lucknow journalist Satyam Verma to move Allahabad high court after fellow NSA accused Aakriti gets relief - The Times of India - September 4th, 2026 [September 4th, 2026]
- NSA Board Dissolution: Olympic, Paralympic representation expected to remain on new board - 3News - September 4th, 2026 [September 4th, 2026]
- NSA Joins FBI in Issuing Warning about Chinese Hacking Group QTFY Cyber Activity - National Security Agency (.gov) - September 2nd, 2026 [September 2nd, 2026]
- NSA and FBI Warn Chinese Hackers Are Actively Targeting US Critical Infrastructure - LinkedIn - September 2nd, 2026 [September 2nd, 2026]
- UP firecracker blast toll climbs to 13; NSA invoked against accused - Daily Pioneer - September 2nd, 2026 [September 2nd, 2026]
- Man Accused of Impersonating Chief Justice Roberts, NSA Agent - Bloomberg Law News - August 25th, 2026 [August 25th, 2026]
- I Worked For The NSA For Years. Here's What Happened To My Life After Donald Trump And DOGE Showed Up Last Year. - HuffPost - August 25th, 2026 [August 25th, 2026]
- NSA isnt complying with federal laws on whistleblower protections, IG finds - Federal News Network - August 25th, 2026 [August 25th, 2026]
- NSA Doval says India-China ties 'returning to normalcy' as he holds key talks with Wang Yi on border issue - The New Indian Express - August 25th, 2026 [August 25th, 2026]
- 4 Ways Tim Kosiba and the NSA Are Countering the Chinese Intelligence Threat - GovCon Wire - August 25th, 2026 [August 25th, 2026]
- Man charged with forging Chief Justice John Robertss signature, impersonating NSA agent - Yahoo - August 25th, 2026 [August 25th, 2026]
- NSA Doval to visit China on Monday to attend Special Representatives talks with FM Wang - The Economic Times - August 25th, 2026 [August 25th, 2026]
- Audit Finds Lack of Oversight of NDAs at NSA - FEDweek - August 25th, 2026 [August 25th, 2026]
- Redefining India-China Relations: NSA Dovals Visit to Beijing May Provide the Breakthrough - Raksha Anirveda - August 25th, 2026 [August 25th, 2026]
- NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology - The Record from Recorded Future News - August 25th, 2026 [August 25th, 2026]
- NSA Doval meets Chinese Vice President Han Zheng ahead of border talks - The Tribune - August 25th, 2026 [August 25th, 2026]
- India-China ties normalised by peace on border, says NSA Doval at talks with Wang Yi - Firstpost - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval holds 25th India-China border talks with Wang Yi - timesofindia.indiatimes.com - August 25th, 2026 [August 25th, 2026]
- NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs - Security Affairs - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval arrives in Beijing, set for border talks with Chinas Wang Yi on August 25 - The Hindu - August 25th, 2026 [August 25th, 2026]
- NSA, FBI Warn of AI-Powered Attacks on Industrial Systems Targeting Siemens PLCs - finance.biggo.com - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval holds talks with Chinese FM Wang Yi on boundary issue - News On AIR - August 25th, 2026 [August 25th, 2026]
- NSA Doval in Beijing for Talks with Chinese FM - Kashmir Observer - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval to hold India-China boundary talks with Wang Yi in Beijing - The New Indian Express - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval to hold border talks with Chinese Foreign Minister Wang on Tuesday - The Tribune - August 25th, 2026 [August 25th, 2026]
- Ayitey Powers Arrested Over Alleged Death Threat Against NSA Boss - Modern Ghana - August 25th, 2026 [August 25th, 2026]
- NSA Doval arrives in Beijing for talks with Chinese FM Wang Yi on boundary issue - ThePrint - August 25th, 2026 [August 25th, 2026]
- Police arrest former boxer Ayitey Powers over alleged death threat on NSA boss - Ghanaian Times - August 25th, 2026 [August 25th, 2026]
- NSA Ajit Doval in Beijing for boundary talks - Awaz The Voice - August 25th, 2026 [August 25th, 2026]
- ID Based on Anonymous Informant, Sudden Reference to 2009 Home Ministry Notification: Why NSA Case Against Satyam Verma Is Unconvincing - TheWire.in - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval: India's Strength Infused with Tolerance Amid Military Actions - India News Network - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval Reveals Operation Sindoor Strategy in New Discovery Docuseries - Daily Pioneer - August 16th, 2026 [August 16th, 2026]
- NSA Ajit Doval on Operation Sindoor: 'India can hit hard, irrespective of consequences' - wionews.com - August 16th, 2026 [August 16th, 2026]
- Indias generosity, tolerance should not be mistaken for weakness: NSA Ajit Doval on Op Sindoor - The Tribune - August 14th, 2026 [August 14th, 2026]
- 'Don't mistake India's generosity with weakness': NSA Ajit Doval on Operation Sindoor - The Times of India - August 14th, 2026 [August 14th, 2026]
- India's generosity, tolerance should not be mistaken for weakness: NSA Ajit Doval on Operation Sindoor - The Hindu - August 14th, 2026 [August 14th, 2026]
- Former NSA Chief Gen. Paul Nakasone: AI Is Changing the Cyber Battlefield - The Cipher Brief - August 14th, 2026 [August 14th, 2026]
- NSA Doval says Indias restraint should not be mistaken for weakness - Awaz The Voice - August 14th, 2026 [August 14th, 2026]
- NSA Ajit Doval says India can hit hard irrespective of consequences in first post-Sindoor interview - The Economic Times - August 14th, 2026 [August 14th, 2026]
- Man claiming to be undercover agent of NSA Ajit Doval arrested in Bihar - The Hindu - August 14th, 2026 [August 14th, 2026]
- Indias tolerance should not be mistaken for weakness; can take risks, hit hard: NSA Doval on Op Sindoor - The Kashmir Horizon - August 14th, 2026 [August 14th, 2026]
- Indias Tolerance Not a Sign of Weakness: NSA Ajit Doval on Operation Sindoor - The CSR Journal - August 14th, 2026 [August 14th, 2026]
- NSA Joins FBI and Others in Releasing Guidance to Defend Against Gunra Ransomware - National Security Agency (NSA) (.gov) - August 12th, 2026 [August 12th, 2026]
- Your router is probably vulnerable to the same attacks the NSA just warned about - MakeUseOf - August 12th, 2026 [August 12th, 2026]
- Trump has to accept hes going to lose Iran war: Former deputy NSA - MS NOW - August 12th, 2026 [August 12th, 2026]
- NSA installs DHS lawyer as new general counsel - The Record from Recorded Future News - August 12th, 2026 [August 12th, 2026]
- Manipur to invoke NSA against NH extortionists: Min - The Times of India - August 12th, 2026 [August 12th, 2026]
- Spymaster United States Joshua Rudd, US special forces officer nursing NSA back to health - Intelligence Online - July 7th, 2026 [July 7th, 2026]
- Capability, Not Compute: NSA Discretion in the Frontier AI EO - The Well News - July 7th, 2026 [July 7th, 2026]
- NSA partners with dog walking app to tackle livestock worrying - Agriland UK - July 1st, 2026 [July 1st, 2026]
- Youth Round Table Discussion: Youth round table discussion held at NSA - Myanmar International TV - July 1st, 2026 [July 1st, 2026]
- NSA welcomes Farming Roadmap 2050 and says farmers are ready to meet the challenge - Meat Management - July 1st, 2026 [July 1st, 2026]
- Crypto Executive Disputes Claims Anthropics Mythos Breached NSA Systems - Yahoo Tech - June 22nd, 2026 [June 22nd, 2026]
- Crypto Executive Disputes Claims Anthropics Mythos Breached NSA Systems - BeInCrypto - June 22nd, 2026 [June 22nd, 2026]
- Its more than Iran could have ever hoped for: Ex-US NSA John Bolton on US-Iran deal - Firstpost - June 22nd, 2026 [June 22nd, 2026]
- Manipur slaps NSA on youth already held under UAPA. Why HC quashed both cases, ordered his release - ThePrint - June 22nd, 2026 [June 22nd, 2026]
- Algorand Post-Quantum Security by 2027: 3 Years Ahead of NSA - The Cryptonomist - June 22nd, 2026 [June 22nd, 2026]
- China foreign minister set to attend Brics NSA meet in Delhi next week - The Times of India - June 22nd, 2026 [June 22nd, 2026]
- India to host BRICS NSA meet on June 2223: MEA - Awaz The Voice - June 22nd, 2026 [June 22nd, 2026]
- IDR Final Rule updates NSA dispute resolution | United States | Global law firm - Norton Rose Fulbright - June 16th, 2026 [June 16th, 2026]
- Where Is Edward Snowden Now? What to Know About the NSA Whistleblower's Life in Exile, 13 Years Later - People.com - June 16th, 2026 [June 16th, 2026]
- Former NSA official: 'Timing couldn't have been worse' for FISA 702 to expire - WBFF - June 16th, 2026 [June 16th, 2026]
- SHAREHOLDER ALERT: The M&A Class Action Firm Continues to Investigate the Merger--CZNL, NSA, CNBN, and ESQ - PR Newswire - June 16th, 2026 [June 16th, 2026]
- Training, teamwork, and quick action save a life at NSA Philadelphia - MilitaryNews.com - June 12th, 2026 [June 12th, 2026]
- NSA Insurance celebrates 100 years of selling a promise on the East End - The Suffolk Times - June 12th, 2026 [June 12th, 2026]
- Ex Pakistan NSA Moeed Yusuf says fixing ties with India key to economic revival, regional trade ambitions - ThePrint - June 12th, 2026 [June 12th, 2026]
- RSABI's Carol McLaren wins NSA Silver Salver for her work in the industry - The Scottish Farmer - June 12th, 2026 [June 12th, 2026]