{"data":{"id":"SC-21","name":"Secure Name/Address Resolution Service (Recursive or Caching Resolver)","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.","supplemental_guidance":"Each client of name resolution services either performs this validation on its own or has authenticated channels to trusted validation providers. Systems that provide name and address resolution services for local clients include recursive resolving or caching domain name system (DNS) servers. DNS client resolvers either perform validation of DNSSEC signatures, or clients use authenticated channels to recursive resolvers that perform such validations. Systems that use technologies other than the DNS to map between host and service names and network addresses provide some other means to enable clients to verify the authenticity and integrity of response data.","enhancements":[{"id":"SC-21(01)","name":"Data Origin and Integrity","withdrawn":true,"incorporated_into":["SC-21"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-21","name":"Secure Name/Address Resolution Service (Recursive or Caching Resolver)","description":"Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.","discussion":"Each client of name resolution services either performs this validation on its own or has authenticated channels to trusted validation providers. Systems that provide name and address resolution services for local clients include recursive resolving or caching domain name system (DNS) servers. DNS client resolvers either perform validation of DNSSEC signatures, or clients use authenticated channels to recursive resolvers that perform such validations. Systems that use technologies other than the DNS to map between host and service names and network addresses provide some other means to enable clients to verify the authenticity and integrity of response data.","related_controls":["SC-20","SC-22"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":["CIS 4.9","CIS 9.2"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.23","SecNumCloud.14.1"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.A(28)","IV.C(62)"],"gdpr":["Art.32(1)(a)"],"dora":["Art.9(4)(a)"],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":["FISC.T3"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":["DNB.18.4"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-8"],"cbuae":["CR-7"],"nca_ecc":["2-5"],"qatar_nia":["CS"],"sama_csf":["3.3"],"uae_ia":["T8"],"bog_cisd":["CISD-VI"],"bom_ctrm":["3.2"],"cbe_csf":["CTO-6"],"cbn_csf":["Part3.3"],"sa_js2":["JS2-7.2"],"bot_cyber":["Ch2.4"],"ecb_croe":["CROE.2.3.5"],"ffiec_is":["II.C.6"],"sebi_cscrf":["PR.NS"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["09.e"],"iso_27799":[],"lloyds_ms":["MS8.9"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.6"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":["NOS-04"],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Secure recursive DNS resolution with origin authentication and integrity verification prevents adversaries from redirecting application layer protocol communications through poisoned DNS responses that resolve C2 domains to attacker-controlled infrastructure."},{"id":"T1568","name":"Dynamic Resolution","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNSSEC validation on recursive resolvers detects and rejects forged DNS responses, undermining dynamic resolution techniques where adversaries use fast-flux or algorithmically generated domains that rely on DNS manipulation to direct traffic to C2 servers."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Authenticated DNS resolution ensures that web protocol C2 traffic reaches only legitimate destinations, preventing DNS cache poisoning attacks that could silently redirect HTTP/HTTPS communications to adversary-controlled servers."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Data origin authentication on DNS responses prevents adversaries from redirecting file transfer protocol C2 channels through poisoned name resolution, ensuring FTP/SFTP connections resolve to legitimate servers rather than attacker infrastructure."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Secure name resolution with integrity verification prevents adversaries from hijacking mail protocol C2 channels by poisoning DNS MX records, ensuring SMTP-based command-and-control traffic cannot be redirected through forged resolution responses."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"DNSSEC validation directly counters DNS-based C2 by authenticating resolution responses, detecting adversary attempts to inject forged DNS records that tunnel commands or exfiltrate data through manipulated DNS query-response pairs."},{"id":"T1568.002","name":"Domain Generation Algorithms","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Secure recursive resolvers with DNSSEC validation can detect anomalous resolution patterns characteristic of domain generation algorithms, and authenticated responses prevent adversaries from poisoning the resolver cache to redirect DGA-resolved domains to their infrastructure."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-016"]}}