EvidenceSheet

NS-10 Ensure Domain Name System (DNS) security

Configure Domain Name System security so clients resolve through trusted authoritative and recursive services and the zones are protected against hijack and dangling records.

4
artefacts
2
held by a system
1
at each review
easy
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Dangling or stale record scan results · Vulnerability scanner / patch tooling
  • DNSSEC or equivalent integrity configuration where supported · Cloud console / configuration management

periodic reviewEvidence produced at each review

  • DNS zone access control and change audit records · Identity provider / directory

governing documentDocuments that govern the control

  • List of authoritative and recursive resolvers in use and their trust basis · Document repository

First move

Automate the pull from your Vulnerability scanner / patch tooling. Scan schedule, findings and remediation age straight from the scanner; patch compliance from the patch console.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

NS-9 Connect on-premises or cloud network privately · PA-1 Separate and limit highly privileged/administrative users