STIGQter STIGQter: STIG Summary: BIND 9.x Security Technical Implementation Guide Version: 3 Release: 3 Benchmark Date: 01 Jul 2026:

The permissions assigned to the core BIND 9.x server files must be set to use the least privilege possible.

DISA Rule

SV-272415r1156956_rule

Vulnerability Number

V-272415

Group Title

SRG-APP-000516-DNS-000099

Rule Version

BIND-9X-001620

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the permissions of each file to the following:

named.conf : rw-r-----
root hints : rw-r-----
Primary zone file(s): rw-rw----
Secondary zone file(s): rw-rw----

Check Contents

With the assistance of the DNS administrator, identify the following files:

named.conf : rw-r-----
root hints : rw-r-----
Primary zone file(s): rw-rw----
Secondary zone file(s): rw-rw----

Note: The name of the root hints file is defined in named.conf. Common names for the file are root.hints, named.cache, or db.cache.

Verify that the permissions for the core BIND 9.x server files are at least as restrictive as listed above.

If the identified files are not as least as restrictive as listed above, this is a finding.

Vulnerability Number

V-272415

Documentable

False

Rule Version

BIND-9X-001620

Severity Override Guidance

With the assistance of the DNS administrator, identify the following files:

named.conf : rw-r-----
root hints : rw-r-----
Primary zone file(s): rw-rw----
Secondary zone file(s): rw-rw----

Note: The name of the root hints file is defined in named.conf. Common names for the file are root.hints, named.cache, or db.cache.

Verify that the permissions for the core BIND 9.x server files are at least as restrictive as listed above.

If the identified files are not as least as restrictive as listed above, this is a finding.

Check Content Reference

M

Target Key

5687