DNS · appears in CAIQ, SIG, ISO 27001
Is DNSSEC enabled on the apex domain?
DNSSEC cryptographically signs DNS responses, blocking cache-poisoning attacks. US federal civilian agencies are required to enable it under OMB M-22-09 (NIST SC-20).
How to answer this
Whichever verdict your domain earns, this is the wording to put in the response box. Reviewers mark an answer down for vagueness more often than for a "No", so say which state you are in and what evidences it.
- Yes
- DNSSEC is enabled and the chain validates
- Partial
- DNSSEC is configured but with validation warnings
- No
- DNSSEC is not enabled on this domain
Controls this evidences
| Framework | Control | Why it maps |
|---|---|---|
| SOC 2 | CC6.6 | DNSSEC prevents DNS cache poisoning. |
| ISO 27001 | A.8.20 | Network controls — DNS integrity. |
| NIST 800-53 | SC-20 | — |
Domain Posture is not an audit and does not replace an auditor. See methodology v1 for how each verdict is reached.
When a "Yes" stops being true
DNSSEC disabled, or the chain of trust stopped validating.
That is the whole problem with answering a questionnaire from a screenshot: the answer was true the day you took it. A signed evidence pack is dated, and a schedule re-checks it so you find out before your reviewer does.