Skip to content

SC-20: Secure Name/Address Resolution Service (Authoritative Source)

An OSCAL Control

Statement

    • a.

      Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and

    • b.

      Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.