{"data":{"id":"SC-20","name":"Secure Name/Address Resolution Service (Authoritative Source)","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"a. Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and\nb. Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.","supplemental_guidance":"Providing authoritative source information enables external clients, including remote Internet clients, to obtain origin authentication and integrity verification assurances for the host/service name to network address resolution information obtained through the service. Systems that provide name and address resolution services include domain name system (DNS) servers. Additional artifacts include DNS Security Extensions (DNSSEC) digital signatures and cryptographic keys. Authoritative data includes DNS resource records. The means for indicating the security status of child zones include the use of delegation signer resource records in the DNS. Systems that use technologies other than the DNS to map between host and service names and network addresses provide other means to assure the authenticity and integrity of response data.","enhancements":[{"id":"SC-20(01)","name":"Child Subspaces","withdrawn":true,"incorporated_into":["SC-20"]},{"id":"SC-20(02)","name":"Data Origin and Integrity","statement":"Provide data origin and integrity protection artifacts for internal name/address resolution queries.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-20","name":"Secure Name/Address Resolution Service (Authoritative Source)","description":"a. Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and\nb. Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.","discussion":"Providing authoritative source information enables external clients, including remote Internet clients, to obtain origin authentication and integrity verification assurances for the host/service name to network address resolution information obtained through the service. Systems that provide name and address resolution services include domain name system (DNS) servers. Additional artifacts include DNS Security Extensions (DNSSEC) digital signatures and cryptographic keys. Authoritative data includes DNS resource records. The means for indicating the security status of child zones include the use of delegation signer resource records in the DNS. Systems that use technologies other than the DNS to map between host and service names and network addresses provide other means to assure the authenticity and integrity of response data.","related_controls":["AU-10","SC-08","SC-12","SC-13","SC-21","SC-22"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":["CIS 4.9","CIS 8.6","CIS 9.2"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.23","SecNumCloud.14.1"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.A(28)","IV.C(62)"],"gdpr":["Art.32(1)(a)"],"dora":["Art.9(4)(a)"],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":["FISC.T3"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":["DNB.18.4"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-8"],"cbuae":["CR-7"],"nca_ecc":["2-5"],"qatar_nia":["CS"],"sama_csf":["3.3"],"uae_ia":["T8"],"bog_cisd":["CISD-VI"],"bom_ctrm":["3.2"],"cbe_csf":["CTO-6"],"cbn_csf":["Part3.3"],"sa_js2":["JS2-7.2"],"bot_cyber":["Ch2.4"],"ecb_croe":["CROE.2.3.5"],"ffiec_is":["II.C.6"],"sebi_cscrf":["PR.NS"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["09.e"],"iso_27799":[],"lloyds_ms":["MS8.9"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.6"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":["NOS-04"],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNSSEC-enabled authoritative name resolution provides data origin authentication and integrity verification for DNS responses, preventing adversaries from exploiting DNS for C2 through spoofed resolution."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Secure name resolution with DNSSEC prevents adversaries from redirecting phishing links through DNS spoofing, ensuring users reach legitimate destinations rather than adversary-controlled infrastructure."},{"id":"T1568","name":"Dynamic Resolution","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Authoritative name resolution with integrity verification disrupts dynamic resolution techniques by preventing adversaries from spoofing DNS responses that redirect C2 communications to dynamically generated domains."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Secure DNS resolution ensures that phishing reconnaissance links resolve to legitimate destinations, preventing DNS-level manipulation that could redirect victims to adversary-controlled credential harvesting sites."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNSSEC verification of domain names used in web protocol C2 ensures adversaries cannot redirect HTTP/HTTPS C2 traffic through DNS spoofing of web-based command-and-control domains."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Secure authoritative name resolution prevents adversaries from redirecting file transfer protocol connections through DNS manipulation, ensuring FTP-based C2 reaches only legitimate destinations."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNSSEC-protected MX record resolution ensures mail server addresses cannot be spoofed through DNS manipulation, preventing adversaries from redirecting email-based C2 traffic through forged mail protocol destination records."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Authoritative DNS with origin authentication and integrity artifacts directly counters DNS-based C2 channels by enabling detection of forged DNS responses used to encode command-and-control data."},{"id":"T1553.004","name":"Install Root Certificate","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Secure name resolution prevents adversaries from redirecting certificate validation traffic through DNS manipulation, ensuring that certificate revocation checks and OCSP queries reach legitimate authorities."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"DNSSEC-protected name resolution ensures that URLs in spearphishing attachments resolve to actual destinations, preventing DNS-level redirection to adversary infrastructure hosting malicious payloads."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Secure authoritative DNS prevents adversaries from hijacking spearphishing link resolution through DNS cache poisoning or spoofing, ensuring links resolve to their true destinations for security evaluation."},{"id":"T1568.002","name":"Domain Generation Algorithms","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Authoritative name resolution with integrity verification makes domain generation algorithm-based C2 unreliable, as DNSSEC-enabled resolvers reject forged responses for adversary-registered DGA domains."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"DNSSEC-protected name resolution ensures that callback URLs in reconnaissance-focused phishing attachments resolve accurately, preventing DNS-level misdirection of information gathering attempts."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Secure DNS resolution prevents adversary manipulation of link destinations in reconnaissance phishing, ensuring that targeted URLs resolve to legitimate sites for proper security evaluation."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-008","SP-016","SP-046"]}}