BIND-9X-001002 - The platform on which the name server software is hosted must only run processes and services needed to support the BIND 9.x implementation.

Information

Hosts that run the name server software should not provide any other services. Unnecessary services running on the DNS server can introduce additional attack vectors leading to the compromise of an organization's DNS architecture.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Disable or uninstall all non-DNS related applications from the BIND 9.x server.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_BIND_9-x_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-207534r879887_rule, STIG-ID|BIND-9X-001002, STIG-Legacy|SV-86991, STIG-Legacy|V-72367, Vuln-ID|V-207534

Plugin: Unix

Control ID: 8b2d0dc5e68cf811f6ef01d1173870a6d03cc55d8f6043eb5f0ef5eb9399a06d