Thecyberexpress
NIST Releases Updated DNS Security Guidance After 12 Years
Article Content
The National Institute of Standards and Technology (NIST) has published SP 800-81r3, the first major update to its DNS security guidance in over twelve years, replacing the 2013 version. This new guidance emphasizes using DNS as an active security control, securing the DNS protocol itself, and protecting the infrastructure supporting DNS services. It introduces the concept of 'protective DNS,' which enhances DNS services with security capabilities to inspect queries, block malicious domains, and generate logs for incident response. The guidance also mandates encrypted DNS for U.S. federal civilian agencies where feasible, addressing protocols such as DNS over TLS, DNS over HTTPS, and DNS over QUIC. Organizations are advised to carefully configure their systems to maintain internal DNS controls amidst the shift to encrypted communications. This update is crucial for both executive decision-makers and operational teams tasked with implementation.
Key Points: • NIST SP 800-81r3 is the first major DNS security update since 2013. • The guidance introduces protective DNS to enhance security capabilities. • Encrypted DNS is mandated for federal agencies, impacting configuration practices.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.