STIGQter STIGQter: STIG Summary: Domain Name System (DNS) Security Requirements Guide Version: 2 Release: 4 Benchmark Date: 23 Oct 2015:

The DNS must utilize valid root name servers in the local root zone file.

DISA Rule

SV-69193r1_rule

Vulnerability Number

V-54947

Group Title

SRG-APP-000516-DNS-000102

Rule Version

SRG-APP-000516-DNS-000102

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DNS implementation to use valid root name servers.

Check Contents

Review the entries within the root hints file and validate that the entries are correct. G and H root servers are required on the NIPRNet, as a minimum. All default settings on servers must be verified and corrected if necessary. If valid root name servers are not configured, this is a finding.

Vulnerability Number

V-54947

Documentable

False

Rule Version

SRG-APP-000516-DNS-000102

Severity Override Guidance

Review the entries within the root hints file and validate that the entries are correct. G and H root servers are required on the NIPRNet, as a minimum. All default settings on servers must be verified and corrected if necessary. If valid root name servers are not configured, this is a finding.

Check Content Reference

M

Target Key

2355

Comments