FedRAMP Controls / SC

SC-20 Secure Name/Address Resolution Service (Authoritative Source)

Family SC
Baselines moderate
Mapped KSIs 2

Control statement

a. Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and
    b. Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.
        Requirement: Control Description should include how DNSSEC is implemented on authoritative DNS servers to supply valid responses to external DNSSEC requests.
        Guidance: SC-20 applies to use of external authoritative DNS to access a CSO from outside the boundary.
        Guidance: External authoritative DNS servers may be located outside an authorized environment. Positioning these servers inside an authorized boundary is encouraged.
        Guidance: CSPs are recommended to self-check DNSSEC configuration through one of many available analyzers such as Sandia National Labs (https://dnsviz.net)

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-IAM-05Least Privilege
_Persistently_ ensure that identity and access management employs measures to ensure each user or device can only access the resources they need.
Identity and Access Management
KSI-SVC-02Network Encryption
Encrypt or otherwise secure network traffic.
Service Configuration