Skip to content

Microsoft Windows Server Domain Name System (DNS) Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000246-DNS-000035

    Group
  • SRG-APP-000247-DNS-000036

    Group
  • The Windows DNS Server must use DNS Notify to prevent denial of service (DoS) through increase in workload.

    In the case of application DoS attacks, care must be taken when designing the application to ensure it makes the best use of system resources. SQL queries have the potential to consume large amount...
    Rule Medium Severity
  • SRG-APP-000439-DNS-000063

    Group
  • SRG-APP-000442-DNS-000067

    Group
  • The Windows DNS Server must maintain the integrity of information during reception.

    Information can be unintentionally or maliciously disclosed or modified during preparation for transmission, including, for example, during aggregation, at protocol transformation points, and durin...
    Rule Medium Severity
  • SRG-APP-000514-DNS-000075

    Group
  • SRG-APP-000251-DNS-000037

    Group
  • The Windows DNS Server must be configured to only allow zone information that reflects the environment for which it is authoritative, including IP ranges and IP versions.

    DNS zone data for which a Windows DNS Server is authoritative should represent the network for which it is responsible. If a Windows DNS Server hosts zone records for other networks or environments...
    Rule Medium Severity
  • SRG-APP-000451-DNS-000069

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules