CIS Controls CIS-4.9

Configure trusted DNS servers on network infrastructure. Example implementations include configuring network devices to use enterprise-controlled DNS servers and/or reputable externally accessible DNS servers. 

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1071.004 DNS
Comments
Directing DNS traffic through trusted enterprise resolvers can prevent systems from communicating directly with adversary-controlled DNS servers and can support blocking or sinkholing malicious DNS requests.
References
    CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1071 Application Layer Protocol
    Comments
    This is a partial mapping because DNS is one of the application-layer protocols covered by this technique. Configuring trusted DNS servers affects DNS-based command and control but does not mitigate web, mail, file-transfer, or publish-subscribe protocols.
    References
      CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1048 Exfiltration Over Alternative Protocol
      Comments
      Enforcing use of trusted DNS resolvers reduces the ability of enterprise assets to communicate directly with adversary-controlled DNS infrastructure for exfiltration. The mitigation applies only to implementations that use DNS or depend on unauthorized DNS servers.
      References
        CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
        Comments
        DNS can carry encoded exfiltrated data over an unencrypted non-command-and-control protocol. Routing requests through controlled resolvers provides an enforcement point for blocking unauthorized DNS servers, suspicious domains, or abnormal query activity.
        References
          CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1572 Protocol Tunneling
          Comments
          DNS can be used to tunnel command-and-control traffic or other protocols. Enforcing trusted resolvers and preventing direct DNS communication can disrupt conventional DNS tunneling,
          References