UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The DNS implementation must notify the appropriate individuals when account disabling actions are taken.


Overview

Finding ID Version Rule ID IA Controls Severity
V-33848 SRG-NET-000010-DNS-000011 SV-44301r1_rule Medium
Description
As most accounts in the DNS are privileged or system level accounts, account management and distribution is vital to the security of the DNS implementation and infrastructure. If an attacker compromises an account, the entire DNS infrastructure, not to mention the hosts on the network, is at risk. Authentication for user or administrative access to the system is required at all times. Accounts are utilized for identifying individual application users or for identifying the application processes themselves. When DNS accounts are terminated, user accessibility may be affected. In order to detect and respond to events that affect user accessibility and application processing, applications must audit account disabling actions and, as required, notify the appropriate individuals so they can investigate the event to ensure its validity. Such a capability greatly reduces the risk that DNS accessibility will be negatively affected for extended periods of time and also provides auditing capability that can be used for forensic purposes.
STIG Date
Domain Name System (DNS) Security Requirements Guide 2012-10-24

Details

Check Text ( C-41905r1_chk )
Review the DNS system and/or configuration files to determine if the system notifies the appropriate individuals when accounts are disabled. If there is not a viewable, configurable option, request the administrator disable an account and verify a notification is sent to the appropriate individuals. If the appropriate individuals are not notified upon account disabling actions, this is a finding.
Fix Text (F-37778r1_fix)
Configure the DNS system to notify appropriate individuals upon account disabling actions.

The account management functions will be performed by the DNS application if the capability exists. If the capability does not exist the underlying platform's account management system may be used.