NS-10 Ensure Domain Name System (DNS) security
Configure Domain Name System security so clients resolve through trusted authoritative and recursive services and the zones are protected against hijack and dangling records.
4
artefacts
2
held by a system
1
at each review
easy
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Dangling or stale record scan results · Vulnerability scanner / patch tooling
- DNSSEC or equivalent integrity configuration where supported · Cloud console / configuration management
periodic reviewEvidence produced at each review
- DNS zone access control and change audit records · Identity provider / directory
governing documentDocuments that govern the control
- List of authoritative and recursive resolvers in use and their trust basis · Document repository
First move
Automate the pull from your Vulnerability scanner / patch tooling. Scan schedule, findings and remediation age straight from the scanner; patch compliance from the patch console.
Common gaps auditors find
- decommissioned resources leaving dangling CNAMEs open to subdomain takeover
- clients allowed to use arbitrary public resolvers
- zone changes made without audit trail
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetNS-9 Connect on-premises or cloud network privately · PA-1 Separate and limit highly privileged/administrative users