FedRAMP Controls / SC

SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)

Family SC
Baselines moderate
Mapped KSIs 2

Control statement

Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.
        Requirement: Control description should include how DNSSEC is implemented on recursive DNS servers to make DNSSEC requests when resolving DNS requests from internal components to domains external to the CSO boundary.

* If the reply is signed, and fails DNSSEC, do not use the reply
* If the reply is unsigned:    * CSP chooses the policy to apply  

        Requirement: Internal recursive DNS servers must be located inside an authorized environment. It is typically within the boundary, or leveraged from an underlying IaaS/PaaS.
        Guidance: Accepting an unsigned reply is acceptable
        Guidance: SC-21 applies to use of internal recursive DNS to access a domain outside the boundary by a component inside the boundary.

* DNSSEC resolution to access a component inside the boundary is excluded.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-IAM-05Least Privilege
_Persistently_ ensure that identity and access management employs measures to ensure each user or device can only access the resources they need.
Identity and Access Management
KSI-SVC-02Network Encryption
Encrypt or otherwise secure network traffic.
Service Configuration