SC-20 Secure Name/Address Resolution Service (Authoritative Source)
Last Review: 10/1/22
Statement
The University information system(s) shall provide authoritative source information for external clients, including remote Internet clients, to obtain origin authentication and integrity verification assurances for University resources.
Applicability
This Control applies to all West Texas A&M network information resources. The intended audience for this Control is the Information Security Team.
Implementation
IT shall ensure systems are configured to meet the following name resolution requirements:
- Provide additional data origin and integrity artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries
- Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.