Skip to content

DNS Security

What is DNS Security?

Measures to protect the Domain Name System from attacks such as DNS spoofing, cache poisoning, and hijacking that redirect users to malicious sites.

Information Security

Each of these is named in at least one of the same controls as dns security. The number is how many controls name both.

What the standards actually require on dns security

Requirements naming dns security across 6 standards, quoted from the control text.

Configure Domain Name System security so clients resolve through trusted authoritative and recursive services and the zones are protected against hijack and dangling records.

ASBv3-NS-10 · Ensure Domain Name System (DNS) security

Security Layer 2 Services per X.805 Clause 7.2: The Services Security Layer is concerned with security of network services that service providers offer to their customers - encompasses the protection of the basic network connectivity services + supplementary v...

X805-Layer2-Services-Security-Frame-Relay-ATM-IP-VoIP-QoS-Toll-Free-IM-VPN-AAA-DNS · ITU-T X.805 Security Layer 2 - Services Security + Frame Relay + ATM + IP + VoIP + QoS + Toll-Free + Instant Messaging + VPN + AAA Authentication-Authorization-Accounting + DNS + IMS + 5G + Cellular Mobile Voice + SMS

Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection...

KNCF-Protect-Network-Configuration-Vulnerability-Physical-Secure-SDLC-Hardening-Patching-Drift · Kuwait NCF Protect + Network + Configuration + Vulnerability + Physical + Secure SDLC

Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-C...

LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15 · Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15

Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for priv...

MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation · MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation

TLD name registries and entities providing domain name registration services carry a dedicated set of duties aimed at DNS security, stability and resilience.

nis2-directive::Art.28 · Maintain accurate domain name registration data and answer lawful access requests within 72 hours

Questions people ask about dns security

What is DNS Security?
Measures to protect the Domain Name System from attacks such as DNS spoofing, cache poisoning, and hijacking that redirect users to malicious sites.
Why is DNS Security important for compliance?
DNS Security is a key concept in Information Security. Understanding dns security helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address DNS Security?
DNS Security appears in the requirement text of Azure Security Benchmark, ITU-T X.805 - Security Architecture for End-to-End Communications, Kuwait National Cybersecurity Framework, Lloyd's Minimum Standards - Cyber Security, Monetary Authority of Singapore Technology Risk Management Guidelines. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about DNS Security?
Explore our compliance framework pages to see how dns security applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how DNS Security applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.