Secure Name/Address Resolution Service (Authoritative Source)
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SC-20 — Secure Name/Address Resolution Service (Authoritative Source). See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-20 — Secure Name/Address Resolution Service (Authoritative Source). See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Providing authoritative source information enables external clients, including remote Internet clients, to obtain origin authentication and integrity verification assurances for the host/service name to network address resolution information obtained through the service. Systems that provide name and address resolution services include domain name system (DNS) servers. Additional artifacts include DNS Security Extensions (DNSSEC) digital signatures and cryptographic keys. Authoritative data includes DNS resource records. The means for indicating the security status of child zones include the use of delegation signer resource records in the DNS. Systems that use technologies other than the DNS to map between host and service names and network addresses provide other means to assure the authenticity and integrity of response data.
Enhancements NIST SOURCE
SC-20(1) Child Subspaces WITHDRAWN
Withdrawn. Incorporated into SC-20.
SC-20(2) Data Origin and Integrity LOW MODERATE HIGH
Provide data origin and integrity protection artifacts for internal name/address resolution queries.
Discussion
None.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SC-20 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- additional data origin authentication is provided along with the authoritative name resolution data that the system returns in response to external name/address resolution queries;
- integrity verification artifacts are provided along with the authoritative name resolution data that the system returns in response to external name/address resolution queries;
- the means to indicate the security status of child zones (and if the child supports secure resolution services) is provided when operating as part of a distributed, hierarchical namespace;
- the means to enable verification of a chain of trust among parent and child domains when operating as part of a distributed, hierarchical namespace is provided.
Examine
[SELECT FROM: System and communications protection policy; procedures addressing secure name/address resolution services (authoritative source); system design documentation; system configuration settings and associated documentation; system security plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel with responsibilities for managing DNS].
Test
[SELECT FROM: Mechanisms supporting and/or implementing secure name/address resolution services].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SC-20. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and communications protection policy
- system security plan
Configuration
- system design documentation
- system configuration settings and associated documentation
Testing
- Mechanisms supporting and/or implementing secure name/address resolution services
Other Records
- procedures addressing secure name/address resolution services (authoritative source)
- other relevant documents or records