Skip to content

I - Mission Critical Public

Rules and Groups employed by this XCCDF Profile

  • The DNS name server software must be at the latest version.

    Each newer version of the name server software, especially the BIND software, generally is devoid of vulnerabilities found in earlier versions because it has design changes incorporated to take car...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The DNS Name Server software must run with restricted privileges.

    Failure to provide logical access restrictions associated with changes to application configuration may have significant effects on the overall security of the system. When dealing with access rest...
    Rule Medium Severity
  • SRG-APP-000516

    Group
  • The IP address for hidden master authoritative name servers must not appear in the name servers set in the zone database.

    A hidden master authoritative server is an authoritative DNS server whose IP address does not appear in the name server set for a zone. All of the name servers that do appear in the zone database ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules