DNS Security
What is DNS Security?
Measures to protect the Domain Name System from attacks such as DNS spoofing, cache poisoning, and hijacking that redirect users to malicious sites.
Terms that appear alongside dns security
Each of these is named in at least one of the same controls as dns security. The number is how many controls name both.
- zero trust 4 shared controls
- dnssec 4 shared controls
- zero trust network access 4 shared controls
- firewall 3 shared controls
- nist 3 shared controls
- gateway 3 shared controls
- dmz 3 shared controls
- microsegmentation 3 shared controls
Frameworks that govern dns security
What the standards actually require on dns security
Requirements naming dns security across 6 standards, quoted from the control text.
Configure Domain Name System security so clients resolve through trusted authoritative and recursive services and the zones are protected against hijack and dangling records.
ASBv3-NS-10 · Ensure Domain Name System (DNS) security →Security Layer 2 Services per X.805 Clause 7.2: The Services Security Layer is concerned with security of network services that service providers offer to their customers - encompasses the protection of the basic network connectivity services + supplementary v...
X805-Layer2-Services-Security-Frame-Relay-ATM-IP-VoIP-QoS-Toll-Free-IM-VPN-AAA-DNS · ITU-T X.805 Security Layer 2 - Services Security + Frame Relay + ATM + IP + VoIP + QoS + Toll-Free + Instant Messaging + VPN + AAA Authentication-Authorization-Accounting + DNS + IMS + 5G + Cellular Mobile Voice + SMS →Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection...
KNCF-Protect-Network-Configuration-Vulnerability-Physical-Secure-SDLC-Hardening-Patching-Drift · Kuwait NCF Protect + Network + Configuration + Vulnerability + Physical + Secure SDLC →Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-C...
LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15 · Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15 →Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for priv...
MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation · MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation →TLD name registries and entities providing domain name registration services carry a dedicated set of duties aimed at DNS security, stability and resilience.
nis2-directive::Art.28 · Maintain accurate domain name registration data and answer lawful access requests within 72 hours →Questions people ask about dns security
What is DNS Security?
Why is DNS Security important for compliance?
Which compliance frameworks address DNS Security?
Where can I learn more about DNS Security?
See how DNS Security applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.