5 - Secure DNS service operating platform

Information

The need for a hardened system is critical to the reliability of the DNS service. This system should be dedicated to running the minimum services required to support DNS.

Rationale:

Since your organization's DNS security is critical to the network services your organization depends on, it needs a dedicated security hardened system with minimal services running.You must also verify that the system is fully patched to prevent attackers from taking advantage of known vulnerabilities in other services.If you combine your DNS server with other services running on the same system, you are aggregating the risk of compromise associated with the additional services.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Harden the operating system, physical location and hardware according to your organization security policies. Run the BIND scoring tool and evaluate the results. All unnecessary services should be disabled, especially high-risk services such as web, mail, FTP, RPC services and file shares such as NFS and SMB.