STIGQter STIGQter: STIG Summary: BIND 9.x Security Technical Implementation Guide Version: 3 Release: 3 Benchmark Date: 01 Jul 2026:

A BIND 9.x server NSEC3 must be used for all internal DNS zones.

DISA Rule

SV-272384r1156952_rule

Vulnerability Number

V-272384

Group Title

SRG-APP-000516-DNS-000084

Rule Version

BIND-9X-001270

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Re-sign each zone that is missing NSEC records.

Restart the BIND 9.x process.

Check Contents

If the server is on an internal, restricted network with reserved IP space, this is Not Applicable.

With the assistance of the DNS administrator, identify each internal DNS zone listed in the "named.conf" file.

For each internal zone identified, inspect the signed zone file for the NSEC resource records:

86400 NSEC example.com. A RRSIG NSEC

If the zone file does not contain an NSEC record for the zone, this is a finding.

Vulnerability Number

V-272384

Documentable

False

Rule Version

BIND-9X-001270

Severity Override Guidance

If the server is on an internal, restricted network with reserved IP space, this is Not Applicable.

With the assistance of the DNS administrator, identify each internal DNS zone listed in the "named.conf" file.

For each internal zone identified, inspect the signed zone file for the NSEC resource records:

86400 NSEC example.com. A RRSIG NSEC

If the zone file does not contain an NSEC record for the zone, this is a finding.

Check Content Reference

M

Target Key

5687