FedRAMP Controls / SC
SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
Family SC
Baselines moderate
Mapped KSIs 2
Control statement
Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.
Requirement: Control description should include how DNSSEC is implemented on recursive DNS servers to make DNSSEC requests when resolving DNS requests from internal components to domains external to the CSO boundary.
* If the reply is signed, and fails DNSSEC, do not use the reply
* If the reply is unsigned: * CSP chooses the policy to apply
Requirement: Internal recursive DNS servers must be located inside an authorized environment. It is typically within the boundary, or leveraged from an underlying IaaS/PaaS.
Guidance: Accepting an unsigned reply is acceptable
Guidance: SC-21 applies to use of internal recursive DNS to access a domain outside the boundary by a component inside the boundary.
* DNSSEC resolution to access a component inside the boundary is excluded. Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-IAM-05 | Least Privilege _Persistently_ ensure that identity and access management employs measures to ensure each user or device can only access the resources they need. | Identity and Access Management |
| KSI-SVC-02 | Network Encryption Encrypt or otherwise secure network traffic. | Service Configuration |