Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Security Strategies for Microservices-based Application Systems: Draft NIST SP 800-204 Available for Comment
March 25, 2019

Microservices architecture is increasingly being used to design, develop, and deploy large-scale application systems in both cloud-based and enterprise infrastructures. The resulting application system consists of relatively small, loosely coupled entities called microservices that communicate with each other using lightweight communication protocols. This smaller codebase facilitates faster code development and platform optimization for which network security, reliability, and latency are critical factors.

NIST invites comments on Draft Special Publication (SP) 800-204, Security Strategies for Microservices-based Application Systems, which outlines strategies for the secure deployment of a microservices-based application. The objective is to enhance its security profile by analyzing 1) the implementation options for core state of practice features, and 2) the configuration options for architectural frameworks such as API gateway and service mesh.  Core features include authentication and access management, service discovery, secure communication protocols, security monitoring, availability/resiliency improvement techniques (e.g., circuit breakers), load balancing and throttling, integrity assurance techniques during induction of new services, and handling of session persistence.

A public comment period for this document is open until April 26, 2019.


NOTE: A call for patent claims is included on page iii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.

Created March 25, 2019, Updated June 22, 2020