Checklist Details for DNS BIND Benchmark Version 1.0

(Archived Revisions)

Checklist Highlights

Checklist Name:
DNS BIND Benchmark
Version:
Version 1.0
Tier:
I
Authority:
  • Third Party: Center for Internet Security (CIS)
Publication Date:
12/31/2005
Automation Expression Information:
XCCDF OVAL CCE CVE CVSS CPE
Supporting Resources:
Target Product:
Target Product CPE Name Product Category
ISC Bind 9.3.1 cpe:/a:isc:bind:9.3.1 (View CVEs)
  • DNS Servers
ISC Bind 9.2.4 cpe:/a:isc:bind:9.2.4 (View CVEs)
  • DNS Servers
Checklist Summary:
This benchmark is intended to assist administrators in securing the BIND (Berkeley Internet Name Domain) an openly redistributable implementation of the Domain Name Service (â??DNSâ?�) protocols. While the majority of the recommendations and steps outlined in this document apply to most Unix systems, it should be noted that specific syntax for some commands will vary for some Unix platforms so the reader is encouraged to be familiar with the differences specific to their individual platforms. The provided excerpts have been tested using BIND 9.3.1 on Red Hat Fedora Core 4 and BIND 9.2.4 on Solaris 10. The configuration and security controls provided have been developed through a consensus effort of best practices recommended by a majority of participating security experts.
		    		
Checklist Role:
  • Domain Name Server
Target Audience:
The audience for the document is at the level of an experienced system administrator, with some specific experience in administering the BIND software.
                	
Comments/Warnings/Miscellaneous:
Refer to Known Issues.
                	
Disclaimer:
Differs for Public and Private consumers, please read disclaimer information from the CIS web site located at:
http://www.cisecurity.org/sub_form.html
	               	
Product Support:
http://www.cisecurity.org/
			    	
Licensing:
Differs for Public and Private consumers, please read licensing information from the CIS web site located at http://www.cisecurity.org/sub_form.html