| Checked | Name | Title |
|---|
| ☐ | SV-259334r960735_rule | The Windows DNS Server must restrict incoming dynamic update requests to known clients. |
| ☐ | SV-259335r1156947_rule | The Windows DNS Server must be configured to record who added/modified/deleted DNS zone information. |
| ☐ | SV-259336r1156948_rule | The Windows DNS Server must notify the DNS administrator in the event of an error validating another DNS server's identity. |
| ☐ | SV-259337r1156965_rule | The Windows DNS Server log must be enabled. |
| ☐ | SV-259338r1028386_rule | The "Manage auditing and security log" user right must be assigned only to authorized personnel. |
| ☐ | SV-259339r961104_rule | The validity period for the Resource Record Signatures (RRSIGs) covering the Delegation Signer (DS) Resource Record (RR) for a zone's delegated children must be no less than two days and no more than one week. |
| ☐ | SV-259340r1156964_rule | The Windows DNS name servers for a zone must be geographically dispersed. |
| ☐ | SV-259341r1156949_rule | The Windows DNS Server must prohibit recursion on authoritative name servers for which forwarders have not been configured for external queries. |
| ☐ | SV-259342r1156949_rule | Forwarders on an authoritative Windows DNS Server, if enabled for external resolution, must forward only to an internal, non-Active Directory (AD)-integrated DNS server or to the DOD Enterprise Recursive Services (ERS). |
| ☐ | SV-259343r1156949_rule | The Windows DNS Server with a caching name server role must restrict recursive query responses to only the IP addresses and IP address ranges of known supported clients. |
| ☐ | SV-259344r1137675_rule | The Windows DNS Server must implement cryptographic mechanisms to detect changes to information during transmission. |
| ☐ | SV-259345r961863_rule | The validity period for the Resource Record Signatures (RRSIGs) covering a zone's DNSKEY RRSet must be no less than two days and no more than one week. |
| ☐ | SV-259346r1156952_rule | NSEC3 must be used for all internal DNS zones. |
| ☐ | SV-259347r961863_rule | The Windows DNS Server's zone files must have NS records that point to active name servers authoritative for the domain specified in that record. |
| ☐ | SV-259348r1156953_rule | All authoritative name servers for a zone must be located on different network segments. |
| ☐ | SV-259349r961863_rule | All authoritative name servers for a zone must have the same version of zone information. |
| ☐ | SV-259350r1156954_rule | The Windows DNS Server must be configured to enable DNSSEC Resource Records (RRs). |
| ☐ | SV-259351r961863_rule | The digital signature algorithm used for DNSSEC-enabled zones must be FIPS-compatible. |
| ☐ | SV-259352r961863_rule | For zones split between the external and internal sides of a network, the resource records (RRs) for the external hosts must be separate from the RRs for the internal hosts. |
| ☐ | SV-259353r961863_rule | In a split DNS configuration between the external and internal networks, the external name server must be configured to not be reachable from inside resolvers. |
| ☐ | SV-259354r961863_rule | Primary authoritative name servers must be configured to only receive zone transfer requests from specified secondary name servers. |
| ☐ | SV-259355r1156956_rule | The Windows DNS Servers zone database files must not be accessible for edit/write by users and/or processes other than the Windows DNS Server service account and/or the DNS database administrator. |
| ☐ | SV-259356r961863_rule | The Windows DNS Server must implement internal/external role separation. |
| ☐ | SV-259357r961863_rule | The Windows DNS Server authoritative for local zones must only point root hints to the DNS servers that host the internal root domain. |
| ☐ | SV-259358r961863_rule | The Windows DNS Servers zone files must not include resource records that resolve to a fully qualified domain name residing in another zone. |
| ☐ | SV-259359r1156962_rule | The Windows DNS Server's zone files must not include CNAME records pointing to a zone with lesser security for more than six months. |
| ☐ | SV-259360r961863_rule | Nonroutable IPv6 link-local scope addresses must not be configured in any zone. |
| ☐ | SV-259361r1018796_rule | AAAA addresses must not be configured in a zone for hosts that are not dual stack. |
| ☐ | SV-259363r960999_rule | The Windows DNS Server must uniquely identify the other DNS server before responding to a server-to-server transaction. |
| ☐ | SV-259364r961503_rule | The secondary Windows DNS name servers must cryptographically authenticate zone transfers from primary name servers. |
| ☐ | SV-259365r960735_rule | The Windows DNS primary server must only send zone transfers to a specific list of secondary name servers. |
| ☐ | SV-259366r1156946_rule | The Windows DNS Server must provide its identity with returned DNS information by enabling DNSSEC and TSIG/SIG(0). |
| ☐ | SV-259367r1212357_rule | The Windows DNS Server must be configured to enforce authorized access to the corresponding private key. |
| ☐ | SV-259368r1212359_rule | The Windows DNS Server key file must be owned by the account under which the Windows DNS Server service is run. |
| ☐ | SV-259370r961041_rule | The private key corresponding to the zone signing key (ZSK) must only be stored on the name server that does support dynamic updates. |
| ☐ | SV-259371r1212361_rule | The Windows DNS Server must implement a local cache of revocation data for PKI authentication. |
| ☐ | SV-259372r961863_rule | The salt value for zones signed using NSEC3 resource records (RRs) must be changed every time the zone is completely re-signed. |
| ☐ | SV-259373r961101_rule | The Windows DNS Server must include data origin with authoritative data the system returns in response to external name/address resolution queries. |
| ☐ | SV-259374r1156950_rule | The Windows DNS Server's IP address must be statically defined and configured locally on the server. |
| ☐ | SV-259375r1156950_rule | The Windows DNS Server must return data information in response to internal name/address resolution queries. |
| ☐ | SV-259376r987696_rule | The Windows DNS Server must use DNSSEC data within queries to confirm data origin to DNS resolvers. |
| ☐ | SV-259377r961581_rule | WINS lookups must be disabled on the Windows DNS Server. |
| ☐ | SV-259378r961581_rule | The Windows DNS Server must use DNSSEC data within queries to confirm data integrity to DNS resolvers. |
| ☐ | SV-259379r961104_rule | The Windows DNS Server must be configured with the Delegation Signer (DS) Resource Records (RR) carrying the signature for the RR that contains the public key of the child zone. |
| ☐ | SV-259380r961107_rule | The Windows DNS Server must enforce approved authorizations between DNS servers using digital signatures in the Resource Record Set (RRSet). |
| ☐ | SV-259381r961107_rule | The Name Resolution Policy Table (NRPT) must be configured in Group Policy to enforce clients to request DNSSEC validation for a domain. |
| ☐ | SV-259382r961107_rule | The Windows DNS Server must be configured to validate an authentication chain of parent and child domains via response data. |
| ☐ | SV-259383r961107_rule | Trust anchors must be exported from authoritative Windows DNS Servers and distributed to validating Windows DNS Servers. |
| ☐ | SV-259384r961107_rule | Automatic Update of Trust Anchors must be enabled on key rollover. |
| ☐ | SV-259385r961584_rule | The Windows DNS secondary servers must request data origin authentication verification from the primary server when requesting name/address resolution. |
| ☐ | SV-259386r961587_rule | The Windows DNS secondary server must request data integrity verification from the primary server when requesting name/address resolution. |
| ☐ | SV-259387r961590_rule | The Windows DNS secondary server must validate data integrity verification on the name/address resolution responses received from primary name servers. |
| ☐ | SV-259388r961593_rule | The Windows DNS secondary server must validate data origin verification authentication on the name/address resolution responses received from primary name servers. |
| ☐ | SV-259389r1043178_rule | The Windows DNS Server must protect the authenticity of zone transfers via transaction signing. |
| ☐ | SV-259390r1043178_rule | The Windows DNS Server must protect the authenticity of dynamic updates via transaction signing. |
| ☐ | SV-259391r1043178_rule | The Windows DNS Server must protect the authenticity of query responses via DNSSEC. |
| ☐ | SV-259392r961596_rule | The Windows DNS Server must use an approved DOD PKI certificate authority. |
| ☐ | SV-259393r1028387_rule | The Windows DNS Server must protect secret/private cryptographic keys while at rest. |
| ☐ | SV-259394r961599_rule | The Windows DNS Server must only contain zone records that have been validated annually. |
| ☐ | SV-259395r961152_rule | The Windows DNS Server must restrict individuals from using it for launching denial-of-service (DoS) attacks against other information systems. |
| ☐ | SV-259396r961155_rule | The Windows DNS Server must use DNS Notify to prevent denial of service (DoS) through increase in workload. |
| ☐ | SV-259397r961632_rule | The Windows DNS Server must protect the integrity of transmitted information. |
| ☐ | SV-259398r961638_rule | The Windows DNS Server must maintain the integrity of information during preparation for transmission. |
| ☐ | SV-259399r961641_rule | The Windows DNS Server must maintain the integrity of information during reception. |
| ☐ | SV-259400r1137676_rule | The Windows DNS Server must implement NIST FIPS-validated cryptography for provisioning digital signatures, generating cryptographic hashes, and protecting unclassified information requiring confidentiality. |
| ☐ | SV-259401r961158_rule | The Windows DNS Server must be configured to only allow zone information that reflects the environment for which it is authoritative, including IP ranges and IP versions. |
| ☐ | SV-259402r1156951_rule | The Windows DNS Server must follow procedures to re-role a secondary name server as the primary name server if the primary name server permanently loses functionality. |
| ☐ | SV-259403r1001264_rule | The DNS Name Server software must be configured to refuse queries for its version information. |
| ☐ | SV-259404r1001265_rule | The HINFO, RP, TXT, and LOC RR types must not be used in the zone SOA. |
| ☐ | SV-259405r1156945_rule | The Windows DNS Server must, when a component failure is detected, activate a notification to the system administrator. |
| ☐ | SV-259406r961734_rule | The Windows DNS Server must verify the correct operation of security functions upon startup and/or restart, upon command by a user with privileged access, and/or every 30 days. |
| ☐ | SV-259407r961734_rule | The Windows DNS Server must verify the correct operation of security functions upon system startup and/or restart, upon command by a user with privileged access, and/or every 30 days. |
| ☐ | SV-259408r961737_rule | The Windows DNS Server must log the event and notify the system administrator when anomalies in the operation of the signed zone transfers are discovered. |
| ☐ | SV-259409r961185_rule | The Windows DNS Server must be configured to notify the information system security officer (ISSO), information system security manager (ISSM), or DNS administrator when functionality of DNSSEC/TSIG has been removed or broken. |
| ☐ | SV-259410r1156963_rule | A unique Transaction Signature (TSIG) key must be generated for each pair of communicating hosts. |
| ☐ | SV-259411r961062_rule | The DNS server implementation must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions. |
| ☐ | SV-259412r961125_rule | In the event of a system failure, the Windows DNS Server must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes. |
| ☐ | SV-259414r1156961_rule | The private keys corresponding to both the zone signing key (ZSK) and the key signing key (KSK) must not be kept on the DNSSEC-aware primary authoritative name server when the name server does not support dynamic updates. |
| ☐ | SV-259415r960948_rule | The Windows DNS Server audit records must be backed up at least every seven days onto a different system or system component than the system or component being audited. |
| ☐ | SV-259416r961863_rule | In a split DNS configuration, where separate name servers are used between the external and internal networks, the internal name server must be configured to not be reachable from outside resolvers. |
| ☐ | SV-259417r961155_rule | Windows DNS response rate limiting (RRL) must be enabled. |