CCI|CCI-001178

Title

Provide additional data origin authentication artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
BIND-9X-001650 - A BIND 9.x server implementation must maintain the integrity and confidentiality of DNS information while it is being prepared for transmission, in transmission, and in use and must perform integrity verification and data origin verification for all DNS information.UnixDISA BIND 9.x STIG v3r1
EX13-EG-000080 - Exchange Internet-facing Send connectors must specify a Smart Host.WindowsDISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6
EX13-MB-000105 - Exchange Internet-facing Send connectors must specify a Smart Host.WindowsDISA Microsoft Exchange 2013 Mailbox Server STIG v2r3
EX16-ED-000160 - Exchange Internet-facing Send connectors must specify a Smart Host.WindowsDISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6
EX16-MB-000210 - Exchange Internet-facing Send connectors must specify a Smart Host.WindowsDISA Microsoft Exchange 2016 Mailbox Server STIG v2r6
EX19-ED-000095 - Exchange internet-facing send connectors must specify a Smart Host.WindowsDISA Microsoft Exchange 2019 Edge Server STIG v2r2
EX19-MB-000106 - Exchange internet-facing send connectors must specify a smart host.WindowsDISA Microsoft Exchange 2019 Mailbox Server STIG v2r3
F5BI-DN-300028 - A BIG-IP DNS server implementation must provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries.F5DISA F5 BIG-IP TMOS DNS STIG v1r1
WDNS-SC-000002 - The Windows 2012 DNS Server must include data origin with authoritative data the system returns in response to external name/address resolution queries.WindowsDISA Microsoft Windows 2012 Server Domain Name System STIG v2r7