Skip to content

II - Mission Support Public

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000001-DNS-000001

    Group
  • Infoblox systems that perform zone transfers to non-Grid DNS servers must limit the number of concurrent sessions for zone transfers.

    Limiting the number of concurrent sessions reduces the risk of denial-of-service (DoS) to the DNS implementation. Infoblox DNS servers configured in a Grid do not use zone transfers. Data is rep...
    Rule Medium Severity
  • SRG-APP-000001-DNS-000115

    Group
  • The Infoblox system must limit the number of concurrent client connections to the number of allowed dynamic update clients.

    Limiting the number of concurrent sessions reduces the risk of denial-of-service (DoS) to the DNS implementation. Name servers do not have direct user connections but accept client connections fo...
    Rule Medium Severity
  • SRG-APP-000333-DNS-000107

    Group
  • The Infoblox DNS server must not reveal sensitive information to an attacker. This includes HINFO, RP, LOC resource, and sensitive TXT record data.

    There are several types of resource records (RRs) in the DNS that are meant to convey information to humans and applications about the network, hosts, or services. These include the Responsible Per...
    Rule Medium Severity
  • SRG-APP-000125-DNS-000012

    Group
  • The Infoblox system audit records must be backed up at least every seven days onto a different system or system component than the system or component being audited.

    Protection of log data includes ensuring that log data is not accidentally lost or deleted. Backing up audit records to a different system or onto separate media than the system being audited on a ...
    Rule Medium Severity
  • SRG-APP-000218-DNS-000027

    Group
  • All authoritative name servers for a zone must be geographically disbursed.

    In addition to network-based dispersion, authoritative name servers should be dispersed geographically as well. In other words, in addition to being located on different network segments, the autho...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules