Domain.Posture

DNS · appears in CAIQ, SIG, ISO 27001

Is DNSSEC enabled on the apex domain?

DNSSEC cryptographically signs DNS responses, blocking cache-poisoning attacks. US federal civilian agencies are required to enable it under OMB M-22-09 (NIST SC-20).

How to answer this

Whichever verdict your domain earns, this is the wording to put in the response box. Reviewers mark an answer down for vagueness more often than for a "No", so say which state you are in and what evidences it.

Yes
DNSSEC is enabled and the chain validates
Partial
DNSSEC is configured but with validation warnings
No
DNSSEC is not enabled on this domain

Controls this evidences

FrameworkControlWhy it maps
SOC 2CC6.6DNSSEC prevents DNS cache poisoning.
ISO 27001A.8.20Network controls — DNS integrity.
NIST 800-53SC-20

Domain Posture is not an audit and does not replace an auditor. See methodology v1 for how each verdict is reached.

When a "Yes" stops being true

DNSSEC disabled, or the chain of trust stopped validating.

That is the whole problem with answering a questionnaire from a screenshot: the answer was true the day you took it. A signed evidence pack is dated, and a schedule re-checks it so you find out before your reviewer does.