{"data":{"id":"SC-22","name":"Architecture and Provisioning for Name/Address Resolution Service","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and external role separation.","supplemental_guidance":"Systems that provide name and address resolution services include domain name system (DNS) servers. To eliminate single points of failure in systems and enhance redundancy, organizations employ at least two authoritative domain name system servers—one configured as the primary server and the other configured as the secondary server. Additionally, organizations typically deploy the servers in two geographically separated network subnetworks (i.e., not located in the same physical facility). For role separation, DNS servers with internal roles only process name and address resolution requests from within organizations (i.e., from internal clients). DNS servers with external roles only process name and address resolution information requests from clients external to organizations (i.e., on external networks, including the Internet). Organizations specify clients that can access authoritative DNS servers in certain roles (e.g., by address ranges and explicit lists).","enhancements":[],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-22","name":"Architecture and Provisioning for Name/Address Resolution Service","description":"Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and external role separation.","discussion":"Systems that provide name and address resolution services include domain name system (DNS) servers. To eliminate single points of failure in systems and enhance redundancy, organizations employ at least two authoritative domain name system servers—one configured as the primary server and the other configured as the secondary server. Additionally, organizations typically deploy the servers in two geographically separated network subnetworks (i.e., not located in the same physical facility). For role separation, DNS servers with internal roles only process name and address resolution requests from within organizations (i.e., from internal clients). DNS servers with external roles only process name and address resolution information requests from clients external to organizations (i.e., on external networks, including the Internet). Organizations specify clients that can access authoritative DNS servers in certain roles (e.g., by address ranges and explicit lists).","related_controls":["SC-02","SC-20","SC-21","SC-24"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":["CIS 4.9"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.23","SecNumCloud.14.1"],"osfi_b13":["B-13.2.2","B-13.3.2"],"finma_circular":["IV.A(28)","IV.C(62)"],"gdpr":["Art.32(1)(a)"],"dora":["Art.9(4)(a)"],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":["FISC.T3"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":["DNB.18.4"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-8"],"cbuae":["CR-7"],"nca_ecc":["2-5"],"qatar_nia":["CS"],"sama_csf":["3.3"],"uae_ia":["T8"],"bog_cisd":["CISD-VI"],"bom_ctrm":["3.2"],"cbe_csf":["CTO-6"],"cbn_csf":["Part3.3"],"sa_js2":["JS2-7.2"],"bcbs_239":["Principle 2"],"bot_cyber":["Ch2.4"],"ecb_croe":["CROE.2.3.5"],"ffiec_is":["II.C.6"],"sebi_cscrf":["PR.NS"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["09.e"],"iso_27799":[],"lloyds_ms":["MS8.9"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.6"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Fault-tolerant DNS architecture with role separation between internal and external resolvers prevents adversaries from leveraging single-point DNS failures to redirect application-layer C2 traffic."},{"id":"T1568","name":"Dynamic Resolution","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Redundant, integrity-protected DNS infrastructure with DNSSEC validation detects and prevents dynamic resolution techniques where adversaries use DNS to locate C2 infrastructure dynamically."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Reliable DNS resolution through redundant authoritative servers ensures that web protocol connections resolve to legitimate endpoints rather than adversary-controlled IP addresses."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Fault-tolerant DNS ensures file transfer protocol connections resolve correctly, preventing adversaries from exploiting DNS failures to redirect FTP sessions to malicious servers."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Redundant DNS with internal/external role separation ensures mail protocol MX record resolution integrity, preventing adversaries from redirecting email through DNS manipulation."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Authoritative DNS architecture with DNSSEC signing and validation directly protects against DNS-based C2 by ensuring query responses have not been forged or manipulated by adversaries."},{"id":"T1568.002","name":"Domain Generation Algorithms","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Fault-tolerant DNS with response policy zones and DNSSEC validation enables detection and blocking of domain generation algorithm queries by identifying anomalous resolution patterns and unsigned responses."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-016"]}}