id: "SC-20" title: "Secure Name/Address Resolution Service (Authoritative Source)" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-20" priority: "P1" implementation_level: "system" enhancements: - sc-20.1 - sc-20.2


Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and

Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.

Guidance

Providing authoritative source information enables external clients, including remote Internet clients, to obtain origin authentication and integrity verification assurances for the host/service name to network address resolution information obtained through the service. Systems that provide name and address resolution services include domain name system (DNS) servers. Additional artifacts include DNS Security Extensions (DNSSEC) digital signatures and cryptographic keys. Authoritative data includes DNS resource records. The means for indicating the security status of child zones include the use of delegation signer resource records in the DNS. Systems that use technologies other than the DNS to map between host and service names and network addresses provide other means to assure the authenticity and integrity of response data.

Assessment Objective: additional data origin authentication is provided along with the authoritative name resolution data that the system returns in response to external name/address resolution queries;

Assessment Objective: integrity verification artifacts are provided along with the authoritative name resolution data that the system returns in response to external name/address resolution queries;

Assessment Objective: the means to indicate the security status of child zones (and if the child supports secure resolution services) is provided when operating as part of a distributed, hierarchical namespace;

Assessment Objective: the means to enable verification of a chain of trust among parent and child domains when operating as part of a distributed, hierarchical namespace is provided.

System and communications protection policy

procedures addressing secure name/address resolution services (authoritative source)

system design documentation

system configuration settings and associated documentation

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with responsibilities for managing DNS

Mechanisms supporting and/or implementing secure name/address resolution services