STIGQter STIGQter: STIG Summary: Domain Name System (DNS) Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 23 Oct 2015:

The DNS implementation must generate audit records for the success and failure of all name server events.

DISA Rule

SV-69157r1_rule

Vulnerability Number

V-54911

Group Title

SRG-APP-000504-DNS-000082

Rule Version

SRG-APP-000504-DNS-000082

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DNS system to log success and failure of zone transfers, zone update notifications, dynamic updates, and start and stop of the name server service or daemon.

Check Contents

Review the DNS system to determine if it is configured to log, at a minimum, success and failure of zone transfers dynamic updates, and start and stop of the name server service or daemon.

If the DNS is not configured to log success and failure of zone transfers, zone update notifications, dynamic updates, and start and stop of the name server service or daemon, this is a finding.

Vulnerability Number

V-54911

Documentable

False

Rule Version

SRG-APP-000504-DNS-000082

Severity Override Guidance

Review the DNS system to determine if it is configured to log, at a minimum, success and failure of zone transfers dynamic updates, and start and stop of the name server service or daemon.

If the DNS is not configured to log success and failure of zone transfers, zone update notifications, dynamic updates, and start and stop of the name server service or daemon, this is a finding.

Check Content Reference

M

Target Key

2355

Comments