SC-21 Secure Name Address Resolution Service (Recursive or Caching Resolver)
Last Review: 10/1/22
Statement
The University information system requests and performs data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.
Applicability
This Control applies to all West Texas A&M network information resources. The intended audience for this Control is the Information Security Team.
Implementation
- An automated mechanism shall be in place that considers the authenticity and data integrity of the DNS trust levels received from authoritative sources.
- WTAMU shall also implement a client-based secure domain name service (DNS) resolution client on all organization-controlled user endpoints.