Domain Name System (DNS) Security Requirements Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
The DNS server implementation must prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization.
<VulnDiscussion>Software and firmware components prevented from installation unless signed with recognized and approved certificates include ...Rule Medium Severity -
SRG-APP-000815
<GroupDescription></GroupDescription>Group -
The DNS server implementation must require users to be individually authenticated before granting access to the shared accounts or resources.
<VulnDiscussion>Individual authentication prior to shared group authentication mitigates the risk of using group accounts or authenticators.&...Rule Medium Severity -
SRG-APP-000820
<GroupDescription></GroupDescription>Group -
The DNS server implementation must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
<VulnDiscussion>The purpose of requiring a device that is separate from the system to which the user is attempting to gain access for one of ...Rule Medium Severity -
SRG-APP-000825
<GroupDescription></GroupDescription>Group -
The DNS server implementation must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.
<VulnDiscussion>A Trusted Platform Module (TPM) is an example of a hardware-protected data store that can be used to protect cryptographic ke...Rule Medium Severity -
SRG-APP-000920
<GroupDescription></GroupDescription>Group -
The DNS server implementation must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that the device meets organization-defined strength of mechanism requirements.
<VulnDiscussion>The purpose of requiring a device that is separate from the system to which the user is attempting to gain access for one of ...Rule Medium Severity -
SRG-APP-000830
<GroupDescription></GroupDescription>Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.