4.3.2 Ensure DNS Filter logs all DNS queries and responses

Information

DNS filter should log all DNS queries and responses.

Rationale:

DNS filter should log all DNS queries and responses (whether the DNS category is blocked, monitored, or allowed). This enables SOC or security analysts to do further investigations on security incidents, especially on threat hunting or incident response activities. Although there are many data sources that can provide DNS query logs (AD or EDR), this option should be enabled out of best practice and with the assumption that no other data source is available.

Impact:

By default, allowed DNS is not logged. This creates a data gap in threat hunting or incident response activities.

Solution

Review DNS Filter Security Profiles and validate that 'Log all DNS queries and responses' is enabled.

Default Value:

Disabled

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-2

Plugin: FortiGate

Control ID: a19452c8b3a0bf32bbc772378366019f5c963f089e3c76dcbc6c512a6820aaf9