UCF STIG Viewer Logo

The network element must employ automated mechanisms to detect the addition of unauthorized components or devices. The monitoring may be accomplished on an ongoing basis or by the periodic scanning. Automated mechanisms can be implemented within the network element and/or in another separate information system or device.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34085 SRG-NET-000134-DNS-NA SV-44538r1_rule Medium
Description
Centrally managing configuration changes for network elements can ensure they are done at the correct time and if necessary in synchronization with each other which can be vital for nodes that peer and require compatible configurations. Centralized configuration management also provides visibility and tracking of enterprise level activity promoting a sound configuration management procedure, as well as an automatic mechanism to track the status of applicable vulnerabilities. Keeping an up-to-date inventory of all network elements and their components provides the framework for the implementation of a comprehensive configuration and problem management system. An inventory of components and their features provides a mechanism for tracking vulnerabilities of effected products which can be used for automated patch management and upgrades. Detection of unauthorized devices via monitoring and scanning is not a function of DNS.
STIG Date
Domain Name System (DNS) Security Requirements Guide 2012-10-24

Details

Check Text ( C-42044r1_chk )
This is not a function of DNS.
Fix Text (F-37995r1_fix)
This requirement is NA for DNS. No fix required.