Secure Name/Address Resolution Service (Authoritative Source)

✓ LOW ✓ MODERATE ✓ HIGH
1 Enhancement 1 Overlay 6 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Providing authoritative source information enables external clients, including remote Internet clients, to obtain origin authentication and integrity verification assurances for the host/service name to network address resolution information obtained through the service. Systems that provide name and address resolution services include domain name system (DNS) servers. Additional artifacts include DNS Security Extensions (DNSSEC) digital signatures and cryptographic keys. Authoritative data includes DNS resource records. The means for indicating the security status of child zones include the use of delegation signer resource records in the DNS. Systems that use technologies other than the DNS to map between host and service names and network addresses provide other means to assure the authenticity and integrity of response data.

Enhancements NIST SOURCE

SC-20(1) Child Subspaces WITHDRAWN

Withdrawn. Incorporated into SC-20.

SC-20(2) Data Origin and Integrity LOW MODERATE HIGH

Provide data origin and integrity protection artifacts for internal name/address resolution queries.

Discussion

None.

Open full page for SC-20(2) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SC-20 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. additional data origin authentication is provided along with the authoritative name resolution data that the system returns in response to external name/address resolution queries;
  2. integrity verification artifacts are provided along with the authoritative name resolution data that the system returns in response to external name/address resolution queries;
  3. the means to indicate the security status of child zones (and if the child supports secure resolution services) is provided when operating as part of a distributed, hierarchical namespace;
  4. the means to enable verification of a chain of trust among parent and child domains when operating as part of a distributed, hierarchical namespace is provided.

Examine

[SELECT FROM: System and communications protection policy; procedures addressing secure name/address resolution services (authoritative source); system design documentation; system configuration settings and associated documentation; system security plan; other relevant documents or records].

Interview

[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel with responsibilities for managing DNS].

Test

[SELECT FROM: Mechanisms supporting and/or implementing secure name/address resolution services].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)

HIGH

  • Base control: Included (matches standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SC-20. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and communications protection policy
  • system security plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Mechanisms supporting and/or implementing secure name/address resolution services

Other Records

  • procedures addressing secure name/address resolution services (authoritative source)
  • other relevant documents or records