← Controls / SC

SC-20 Secure Name/Address Resolution Service (Authoritative Source)

System and Communications Protection

Low Moderate High

Description

a. Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and b. Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.

Supplemental Guidance

Providing authoritative source information enables external clients, including remote Internet clients, to obtain origin authentication and integrity verification assurances for the host/service name to network address resolution information obtained through the service. Systems that provide name and address resolution services include domain name system (DNS) servers. Additional artifacts include DNS Security Extensions (DNSSEC) digital signatures and cryptographic keys. Authoritative data includes DNS resource records. The means for indicating the security status of child zones include the use of delegation signer resource records in the DNS. Systems that use technologies other than the DNS to map between host and service names and network addresses provide other means to assure the authenticity and integrity of response data.

Enhancements (1)

What NIST adds to this control. Select one to read its statement.

SC-20(02) Data Origin and Integrity

Provide data origin and integrity protection artifacts for internal name/address resolution queries.

Withdrawn by NIST:

  • SC-20(01) Child Subspaces, now in SC-20

Patterns that use this control (3)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

CIS Controls v8

CIS 4.9CIS 8.6CIS 9.2

ANSSI

Hygiene.23SecNumCloud.14.1

FINMA Circular 2023/1

IV.A(28)IV.C(62)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(a)

EU DORA

Art.9(4)(a)

RBI CSF

Annex1.4

FISC Security Guidelines

FISC.T3

DNB Good Practice

DNB.18.4

SAMA CSF

3.3

NCA ECC

2-5

UAE IA

T8

CBB TM

TM-8

Qatar NIA

CS

CBUAE

CR-7

CBE CSF

CTO-6

SA JS2

JS2-7.2

CBN CSF

Part3.3

BoG CISD

CISD-VI

BoM CTRM

3.2

FFIEC IS

II.C.6

ECB CROE

CROE.2.3.5

SEBI CSCRF

PR.NS

BOT Cyber Resilience

Ch2.4

CMMC 2.0

SC

Solvency II

EIOPA-ICT-4.6

Lloyd's Minimum Standards

MS8.9

HITRUST CSF v11

09.e

BSSC Standards

NOS-04

ISO 17799 (legacy)

None.

COBIT 4.1 (legacy)

None.