| Checked | Name | Title |
|---|
| ☐ | SV-233855r1082600_rule | Infoblox systems that perform zone transfers to non-Grid DNS service members must limit the number of concurrent sessions for zone transfers. |
| ☐ | SV-233856r960735_rule | The Infoblox system must limit the number of concurrent client connections to the number of allowed dynamic update clients. |
| ☐ | SV-233857r1082603_rule | The Infoblox DNS service member must not reveal sensitive information to an attacker. This includes Host Information (HINFO), Responsible Person (RP), Location (LOC) resource, and sensitive text string resource (TXT) record data. |
| ☐ | SV-233858r960948_rule | The Infoblox system audit records must be backed up at least every seven days onto a different system or system component than the system or component being audited. |
| ☐ | SV-233859r1156964_rule | All authoritative DNS service members for a zone must be geographically dispersed. |
| ☐ | SV-233860r1156949_rule | Recursion must be disabled on Infoblox DNS service members that are configured as External Authoritative DNS service members. |
| ☐ | SV-233861r961863_rule | The validity period for the Resource Record Signatures (RRSIGs) covering a zone's DNSKEY RRSet must be no less than two days and no more than one week. |
| ☐ | SV-233862r1156952_rule | NSEC3 must be used for all DNSSEC signed zones. |
| ☐ | SV-233863r1082996_rule | The Infoblox DNS service member must be configured so that each DNS service member record in a zone file points to an active DNS service member authoritative for the domain specified in that record. |
| ☐ | SV-233864r1156953_rule | All authoritative DNS service members for a zone must be located on different network segments. |
| ☐ | SV-233865r1082621_rule | All authoritative DNS service members for a zone must have the same version of zone information. |
| ☐ | SV-233866r1156954_rule | An External authoritative DNS service member must be configured to enable DNSSEC resource records. |
| ☐ | SV-233867r1082626_rule | The digital signature algorithm used for DNSSEC-enabled zones must be FIPS-compatible. |
| ☐ | SV-233868r1082629_rule | For zones split between the external and internal sides of a network, the resource records (RRs) for the external hosts must be separate from the RRs for the internal hosts. |
| ☐ | SV-233869r1082632_rule | In a split DNS configuration, where separate DNS service members are used between the external and internal networks, the external DNS service member must be configured to not be reachable from inside resolvers. |
| ☐ | SV-233870r1082635_rule | In a split DNS configuration, where separate DNS service members are used between the external and internal networks, the internal DNS service member must be configured to not be reachable from outside resolvers. |
| ☐ | SV-233871r1082637_rule | Primary authoritative DNS service members must be configured to only receive zone transfer requests from specified secondary DNS service members. |
| ☐ | SV-233872r1156956_rule | The Infoblox system must use a security policy that limits the propagation of access rights. |
| ☐ | SV-233873r1082640_rule | The DNS implementation must implement internal/external role separation. |
| ☐ | SV-233874r1082643_rule | The Infoblox DNS service member must use current and valid root DNS service members. |
| ☐ | SV-233875r1156957_rule | The Infoblox NIOS version must be at the appropriate version. |
| ☐ | SV-233876r1082648_rule | The IP address for hidden master authoritative DNS service members must not appear in the DNS service members set in the zone database. |
| ☐ | SV-233877r1156959_rule | The Infoblox system must be configured to respond to DNS traffic only. |
| ☐ | SV-233878r1082650_rule | The Infoblox DNS service member must send outgoing DNS messages from a random port. |
| ☐ | SV-233879r1156961_rule | The private keys corresponding to both the Zone Signing Key (ZSK) and the Key Signing Key (KSK) must not be kept on the DNSSEC-aware primary authoritative DNS service member when the DNS service member does not support dynamic updates. |
| ☐ | SV-233880r1156962_rule | CNAME records must not point to a zone with lesser security for more than six months. |
| ☐ | SV-233882r961863_rule | A secure out-of-band (OOB) network must be used for management of Infoblox Grid Members. |
| ☐ | SV-233883r961863_rule | Infoblox systems must enforce current DoD password restrictions. |
| ☐ | SV-233884r961863_rule | Infoblox Grid configuration must be backed up on a regular basis. |
| ☐ | SV-233885r961863_rule | The Infoblox system must display the approved DoD notice and consent banner. |
| ☐ | SV-233886r961863_rule | The Infoblox system must display the appropriate security classification information. |
| ☐ | SV-233887r961863_rule | The Infoblox system must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs. |
| ☐ | SV-233888r1082658_rule | The Infoblox system must present only approved TLS and SSL cipher suites. |
| ☐ | SV-233889r1156946_rule | An Infoblox DNS service member must strongly bind the identity of the DNS service member with the DNS information using DNSSEC. |
| ☐ | SV-233890r1156947_rule | The Infoblox system must provide the means for authorized individuals to determine the identity of the source of the DNS service member-provided information. |
| ☐ | SV-233891r1082667_rule | The Infoblox system must validate the binding of the other DNS service members' identity to the DNS information for a server-to-server transaction (e.g., zone transfer). |
| ☐ | SV-233892r1156948_rule | The Infoblox system must send a notification in the event of an error when validating the binding of another DNS service member's identity to the DNS information. |
| ☐ | SV-233893r1156950_rule | The Infoblox DNS service member must provide data origin artifacts for internal name/address resolution queries. |
| ☐ | SV-233894r1082674_rule | The Infoblox DNS service member must provide data integrity protection artifacts for internal name/address resolution queries. |
| ☐ | SV-233895r1156945_rule | The Infoblox system must notify the system administrator when a component failure is detected. |
| ☐ | SV-233896r1156951_rule | The Infoblox DNS service member implementation must follow procedures to promote a secondary DNS service member to the role of primary DNS service member in the event the current primary DNS service member permanently loses functionality. |
| ☐ | SV-233897r1082679_rule | The Infoblox system must prohibit or restrict unapproved services, ports, and protocols. |
| ☐ | SV-233898r1082682_rule | The Infoblox system must require devices to reauthenticate for each zone transfer and dynamic update request connection attempt. |
| ☐ | SV-233899r1082685_rule | When using third-party DNS servers for zone transfers, each DNS server must use TSIG to uniquely identify the other server. |
| ☐ | SV-233900r1082688_rule | The Infoblox DNS service member must authenticate to any external (non-Grid) DNS service members before responding to a server-to-server transaction. |
| ☐ | SV-233901r1082691_rule | The Infoblox DNS service member must authenticate another DNS service member before establishing a remote and/or network connection using bidirectional authentication that is cryptographically based. |
| ☐ | SV-233902r1156963_rule | Infoblox systems that communicate with non-Grid DNS service members must use a unique Transaction Signature (TSIG). |
| ☐ | SV-233903r1082697_rule | The Infoblox Grid Master must be configured as a stealth (hidden) domain DNS service member to protect the Key Signing Key (KSK) residing on it. |
| ☐ | SV-233904r1083000_rule | The Infoblox Grid Master must be configured as a stealth (hidden) domain DNS service member in order to protect the Zone Signing Key (ZSK) residing on it. |
| ☐ | SV-233905r961062_rule | The Infoblox system must employ strong authenticators in the establishment of non-local maintenance and diagnostic sessions. |
| ☐ | SV-233906r1137676_rule | The Infoblox DNS service member must implement NIST FIPS-validated cryptography for provisioning digital signatures, generating cryptographic hashes, and protecting unclassified information requiring confidentiality. |
| ☐ | SV-233907r961101_rule | The Infoblox system must provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries. |
| ☐ | SV-233908r1082705_rule | The Infoblox DNS service member must provide additional integrity artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries. |
| ☐ | SV-233909r1082708_rule | The Infoblox DNS service member implementation must provide the means to indicate the security status of child zones. |
| ☐ | SV-233910r961104_rule | The validity period for the Resource Record Signatures (RRSIGs) covering the Delegation Signer (DS) RR for a zone's delegated children must be no less than two days and no more than one week. |
| ☐ | SV-233911r1082711_rule | The Infoblox DNS service member implementation must enforce approved authorizations for controlling the flow of information between DNS service members and between DNS service members and DNS clients based on TSIG policies. |
| ☐ | SV-233912r1083002_rule | The Infoblox DNS service member must enable verification of a chain of trust among parent and child domains (if the child supports secure resolution services). |
| ☐ | SV-233913r1082717_rule | The Infoblox DNS service member must request data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources. |
| ☐ | SV-233917r1082725_rule | Infoblox DNS service members must protect the authenticity of communications sessions for zone transfers when communicating with external DNS service members (i.e., DNS systems outside the Infoblox grid). |
| ☐ | SV-233918r1082728_rule | Infoblox DNS service members must protect the authenticity of communications sessions for dynamic updates. |
| ☐ | SV-233919r1082730_rule | Infoblox DNS service members must protect the authenticity of communications sessions for queries. |
| ☐ | SV-233920r961125_rule | In the event of a system failure, the Infoblox system must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes. |
| ☐ | SV-233921r1082733_rule | The Infoblox system must restrict the ability of individuals to use the DNS service member to launch denial-of-Service (DoS) attacks against other information systems. |
| ☐ | SV-233922r1082735_rule | The Infoblox system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information-flooding types of denial-of-service (DoS) attacks. |
| ☐ | SV-233923r1082737_rule | The Infoblox DNS service member must protect the integrity of transmitted information. |
| ☐ | SV-233924r1137675_rule | The Infoblox DNS service member must implement cryptographic mechanisms to detect changes to information during transmission unless otherwise protected by alternative physical safeguards, such as, at a minimum, a Protected Distribution System (PDS). |
| ☐ | SV-233925r1082741_rule | The Infoblox DNS service member implementation must maintain the integrity of information during preparation for transmission. |
| ☐ | SV-233926r1082744_rule | The Infoblox DNS service member implementation must maintain the integrity of information during reception. |
| ☐ | SV-233927r961185_rule | The Infoblox system must notify the ISSO and ISSM in the event of failed security verification tests. |
| ☐ | SV-233928r1082747_rule | The Infoblox DNS service member implementation must log the event and notify the system administrator when anomalies in the operation of the signed zone transfers are discovered. |