UCF STIG Viewer Logo

The DNS implementation must isolate security functions from non-security functions.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34135 SRG-NET-000184-DNS-000112 SV-44588r1_rule Medium
Description
Security functions are defined as ""the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based"". If the security functions were to be undermined, the DNS implementation could be compromised. DNS implementers can increase the assurance in security functions by employing well-defined security policy models, structured, disciplined, and rigorous hardware and software development techniques, and sound system/security engineering principles. The DNS element must isolate security functions from non-security functions by means of an isolation boundary (implemented via partitions and domains) controlling access to and protecting the integrity of, the hardware, software, and firmware performing those security functions. The DNS element must maintain a separate execution domain (e.g., address space) for each executing process.
STIG Date
Domain Name System (DNS) Security Requirements Guide 2012-10-24

Details

Check Text ( C-42095r1_chk )
Responsibility for separation of security functions is the responsibility of the operating system, application design and configuration settings.

Verify the platform on which the implementation rests, including hardware and operating system, support separation of security functions. Compliance to the appropriate DISA operating system STIG will facilitate this check.

Review the DNS vendor documentation to determine if the design of the DNS software takes advantage of the separate security functions provided by the underlying platform.

Verify any DNS system configuration settings that are required to take advantage of isolated security functions in support the DNS server are made.

If isolation does not exist between security and non-security functions, this is a finding.
Fix Text (F-38045r1_fix)
Ensure the DNS implementation is capable of, and configured in such a way that security functions are isolated from non-security functions.