Skip to content

Refresh DNS security baseline to NIST SP 800-81 Rev. 3#1669

Open
yanziwei wants to merge 1 commit into
UnitOneAI:mainfrom
yanziwei:improve/dns-security-nist-rev3-refresh
Open

Refresh DNS security baseline to NIST SP 800-81 Rev. 3#1669
yanziwei wants to merge 1 commit into
UnitOneAI:mainfrom
yanziwei:improve/dns-security-nist-rev3-refresh

Conversation

@yanziwei
Copy link
Copy Markdown

@yanziwei yanziwei commented Jun 7, 2026

Summary

Addresses #200.

  • refresh dns-security metadata and framework references from NIST SP 800-81 Rev. 2 to Rev. 3
  • add revision-aware reporting fields, including publication URL, legacy baseline justification, and evidence collection timestamp
  • align DNSSEC, encrypted DNS, protective DNS, DNS logging, and recursive resolver checks to Rev. 3 section structure
  • add DNS over QUIC, expanded resolver discovery, DNS logging/privacy checks, and zero trust/defense-in-depth framing

Validation

  • git diff --check
  • Markdown fence-balance check
  • marker checks for NIST-SP-800-81-Rev3, DNS over QUIC, DNS Logging and Monitoring, Protective DNS and Logging, and legacy baseline fields

Notes

The implementation keeps this to a single-file baseline refresh so it is easy to review against the existing #200 gap. It preserves a legacy Rev. 2 justification field for teams that must intentionally run an older baseline.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant