Back to catalog
NET-10NETNetwork Security
Domain Name Service (DNS) Resolution
Description
Mechanisms exist to ensure Domain Name Service (DNS) resolution is designed, implemented and managed to protect the security of name / address resolution.
Cross-Mappings
68 paths across 3 frameworks
Cross-Mappings
NIST 800-532 mappings
CCI6 mappings
CCI-001178
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001179
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001663
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002462
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002463
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002464
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG43 mappings
SV-205176r961101_ruleA DNS server implementation must provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205177r961104_ruleA DNS server implementation must provide the means to indicate the security status of child zones.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205178r961104_ruleThe validity period for the RRSIGs covering the DS RR for a zones delegated children must be no less than two days and no more than one week.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205179r961107_ruleThe DNS server implementation must enforce approved authorizations for controlling the flow of information between DNS servers and between DNS servers and DNS clients based on DNSSEC policies.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205180r961107_ruleA DNS server implementation must provide the means to enable verification of a chain of trust among parent and child domains (if the child supports secure resolution services).
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205207r987696_ruleA DNS server implementation must provide data integrity protection artifacts for internal name/address resolution queries.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-205208r961581_ruleA DNS server implementation must provide additional integrity artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 4 · disa_xccdf · related
SV-207577r879633_ruleA BIND 9.x server implementation must maintain the integrity and confidentiality of DNS information while it is being prepared for transmission, in transmission, and in use and t must perform integrity verification and data origin verification for all DNS information.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-207578r879634_ruleA BIND 9.x server implementation must provide the means to indicate the security status of child zones.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-207579r879634_ruleThe BIND 9.x server validity period for the RRSIGs covering the DS RR for zones delegated children must be no less than two days and no more than one week.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
+33 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer