Cybersecurity GRC 14 items
DNS Security Controls Review
Reviews DNS security controls across resolver protection, DNSSEC, protective filtering, logging, and registrar/zone integrity to defend against tunneling, hijacking, and abuse.
NIST 800-81NIST 800-53CIS v8
Free PDF · enter your email to download.
Resolver & Filtering
- Are endpoints restricted to approved internal or protective DNS resolvers? *
- Is protective DNS filtering used to block known-malicious domains? *
- Is outbound DNS to unauthorized external resolvers blocked at the firewall? *
- Is encrypted DNS (DoH/DoT) governed by policy rather than uncontrolled?
DNSSEC & Integrity
- Is DNSSEC signing enabled for authoritative zones you control? *
- Is DNSSEC validation enabled on recursive resolvers? *
- Are DNSSEC keys rotated and DS records maintained at the registrar?
Registrar & Zone Protection
- Is registrar/registry lock enabled to prevent unauthorized domain transfers? *
- Is MFA enforced on registrar and DNS management accounts? *
- Are zone changes subject to change control and review?
- Are critical domain expiration dates monitored and auto-renewal enabled?
Monitoring & Detection
- Are DNS query logs collected and retained for analysis? *
- Is DNS tunneling and anomalous query behavior monitored? *
- Are newly registered and typosquat lookalike domains monitored?
Download the full DNS Security Controls Review checklist
Get it as a clean, printable PDF — free.
