DISA BIND 9.x STIG v1r9

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA BIND 9.x STIG v1r9

Updated: 2/7/2022

Authority: DISA STIG

Plugin: Unix

Revision: 1.6

Estimated Item Count: 104

Audit Changelog

 
Revision 1.6

Feb 7, 2022

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.5

Jul 30, 2021

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.4

Jun 17, 2021

Miscellaneous
  • Metadata updated.
Revision 1.3

Mar 23, 2021

Functional Update
  • BIND-9X-001054 - A BIND 9.x server implementation must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of Denial of Service (DoS) attacks - zone allow-query
  • BIND-9X-001055 - A BIND 9.x server implementation must prohibit recursion on authoritative name servers - zone allow-query
  • BIND-9X-001057 - The master servers in a BIND 9.x implementation must notify authorized secondary name servers when zone files are updated - zone also-notify
  • BIND-9X-001057 - The master servers in a BIND 9.x implementation must notify authorized secondary name servers when zone files are updated - zone notify explicit
  • BIND-9X-001058 - The secondary name servers in a BIND 9.x implementation must be configured to initiate zone update notifications to other authoritative zone name servers - zone allow-notify
  • BIND-9X-001058 - The secondary name servers in a BIND 9.x implementation must be configured to initiate zone update notifications to other authoritative zone name servers - zone notify explicit
  • BIND-9X-001080 - A BIND 9.x implementation configured as a caching name server must restrict recursive queries to only the IP addresses and IP address ranges of known supported clients - allow-query
  • BIND-9X-001080 - A BIND 9.x implementation configured as a caching name server must restrict recursive queries to only the IP addresses and IP address ranges of known supported clients - allow-recursion
  • BIND-9X-001106 - The BIND 9.x server implementation must utilize separate TSIG key-pairs when securing server-to-server transactions - key
Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.2

Sep 29, 2020

Miscellaneous
  • References updated.
Revision 1.1

Jul 14, 2020

Miscellaneous
  • Metadata updated.