WDNS-SC-000025 - The Windows 2012 DNS Server must not contain zone records that have not been validated in over a year.

Information

If zone information has not been validated in over a year, then there is no assurance that it is still valid. If invalid records are in a zone, then an adversary could potentially use their existence for improper purposes. An SOP detailing this process can resolve this requirement.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Create a separate database to maintain record documentation for non-AD-integrated zones.

Develop a procedure to validate annually all zone information on the DNS server against the separately maintained database.

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Press Windows Key + R, execute dnsmgmt.msc.

On the opened DNS Manager snap-in from the left pane, expand the server name for the DNS server, and then expand Forward Lookup Zones.

From the expanded list, click to select the zone.

Select the zone records which have not been validated in over a year and revalidate.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_Server_DNS_V2R7_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CAT|I, CCI|CCI-002475, Rule-ID|SV-215631r961599_rule, STIG-ID|WDNS-SC-000025, STIG-Legacy|SV-73125, STIG-Legacy|V-58695, Vuln-ID|V-215631

Plugin: Windows

Control ID: 5a9d4b9e601c3f9619b95e68bdda473464b803155ff9cd99a668bf063d9d18be