SV-69057r1_rule
V-54811
SRG-APP-000176-DNS-000096
SRG-APP-000176-DNS-000096
CAT II
10
Create operation documentation to include the safe management of keys and key storage within the DNS implementation. Include in the documentation steps to ensure signature generation using the KSK are done off-line, using the KSK-private stored off-line or the secure, protected module.
Verify the DNS operational procedures and confirm procedures exist to enforce generating signatures using the KSK are performed off-line, using the KSK-private stored off-line or the secure, protected module.
If the procedures do not exist or the procedures do not specify to perform the signature generation off-line from the name server, this is a finding.
V-54811
False
SRG-APP-000176-DNS-000096
Verify the DNS operational procedures and confirm procedures exist to enforce generating signatures using the KSK are performed off-line, using the KSK-private stored off-line or the secure, protected module.
If the procedures do not exist or the procedures do not specify to perform the signature generation off-line from the name server, this is a finding.
M
2355