Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-34232 | SRG-NET-000267-DNS-000146 | SV-44710r1_rule | Medium |
Description |
---|
DNS security functional testing involves testing the system for conformance to the applications security function specifications, as well as, for the underlying security model. The need to verify security functionality applies to all security functions. For those security functions that are not able to execute automated self-tests, the organization either implements compensating security controls or explicitly accepts the risk of not performing the verification as required. System initialization, shutdown, and aborts must be configured to ensure the system remains in a secure state. If tests are not provided and periodically run, the integrity of the system state cannot be verified. |
STIG | Date |
---|---|
Domain Name System (DNS) Security Requirements Guide | 2012-10-24 |
Check Text ( C-42215r1_chk ) |
---|
Review the DNS vendor documentation and system configuration to determine if the correct operation of security functions, in accordance with organization defined conditions and frequency, is verified. If the correct operation of organization defined security functions cannot be verified, this is a finding. |
Fix Text (F-38163r1_fix) |
---|
Ensure the DNS system verifies the correct operation of security functions in accordance with organization defined conditions and frequency. |