STIGQter STIGQter: STIG Summary: Domain Name System (DNS) Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 23 Oct 2015:

The DNS server implementation must be configured to provide audit record generation capability for DoD-defined auditable events within all DNS server components.

DISA Rule

SV-69027r1_rule

Vulnerability Number

V-54781

Group Title

SRG-APP-000089-DNS-000004

Rule Version

SRG-APP-000089-DNS-000004

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DNS server to generate events for successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g., classification levels) events within all DNS server components.

Check Contents

Review the DNS server implementation configuration to determine if the DNS server is configured to generate audit events for successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g., classification levels) events within all DNS server components.

If the DNS server is not configured to generate audit events for successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g., classification levels) events within all DNS server components, this is a finding.

Vulnerability Number

V-54781

Documentable

False

Rule Version

SRG-APP-000089-DNS-000004

Severity Override Guidance

Review the DNS server implementation configuration to determine if the DNS server is configured to generate audit events for successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g., classification levels) events within all DNS server components.

If the DNS server is not configured to generate audit events for successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g., classification levels) events within all DNS server components, this is a finding.

Check Content Reference

M

Target Key

2355

Comments