Skip to content

I - Mission Critical Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000516-DNS-000078

    <GroupDescription></GroupDescription>
    Group
  • The Zone Signing Key (ZSK) rollover interval must be configured to less than two months.

    &lt;VulnDiscussion&gt;An attacker that has compromised a ZSK can use that key only during the KSK's signature validity interval. An attacker that h...
    Rule Medium Severity
  • SRG-APP-000516-DNS-000084

    <GroupDescription></GroupDescription>
    Group
  • NSEC3 must be used for all internal DNS zones.

    &lt;VulnDiscussion&gt;To ensure that RRs associated with a query are really missing in a zone file and have not been removed in transit, the DNSSEC...
    Rule Medium Severity
  • SRG-APP-000516-DNS-000085

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules