{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Network & Communications Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-07","description":"Provide authoritative name-resolution service with origin authentication and integrity verification (e.g., DNSSEC), and perform data-origin authentication and integrity validation in recursive or caching resolvers. Architect name-resolution services to be fault tolerant and to enforce internal and external role separation, and synchronize system clocks to authoritative time sources so events can be correlated reliably.","details":{"control_category":"technical","control_type":"preventive","domain":"Network & Communications Security","guidance":[],"members":[{"control_id":"SC-20","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-21","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-22","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-45","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Provide authoritative name-resolution service with origin authentication and integrity verification (e.g., DNSSEC), and perform data-origin authentication and integrity validation in recursive or caching resolvers. Architect name-resolution services to be fault tolerant and to enforce internal and external role separation, and synchronize system clocks to authoritative time sources so events can be correlated reliably.","title":"Secure name resolution and time services","unified_id":"UC-NET-07"},"id":"uc:UC-NET-07","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-07","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-NET-07 — Secure name resolution and time services","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e3ac8e4c97f738183cf32c50e9ea33938466091c2daf33d793f114dadd35098","properties":{"control_id":"SC-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-20-534627dd.json","targetId":"ctrl:nist-800-53:SC-20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:137db857c1c648f7bd5f985bb47bb4e196a8e7300be980cf414205f88981f8c4","properties":{"rationale":"DNSSEC data-origin authentication and integrity validation in resolvers prevent acceptance of spoofed or cache-poisoned name-resolution data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/risk-net-untrustworthy-input-data-6465a381.json","targetId":"risk:net-untrustworthy-input-data","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1734cd2bfc119a9197c79da45a6e6b1f8b07b6a7e3e4fc2f3e67275a728d1224","properties":{"rationale":"Architecting name-resolution services to be fault tolerant removes a name-service single point of failure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/risk-bcdr-single-point-concentration-91008453.json","targetId":"risk:bcdr-single-point-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:250ff003f4b715eb5d0786b51acc43c0e458ca085b40ac375477d3b7a93a58b4","properties":{"control_id":"SC-21","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-21-720f7e8e.json","targetId":"ctrl:nist-800-53:SC-21","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:29839c3acb7b642fd5676a76d543bf1cca24b8b4255460b9740880acca326548","properties":{"control_id":"SC-45","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-45-927bedb6.json","targetId":"ctrl:nist-800-53:SC-45","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2b27d6601dcf4e126d3164477830bc8bb8111f97b1645d9a804900c159461f6e","properties":{"rationale":"Authenticated, integrity-verified name resolution prevents DNS spoofing/redirection that enables man-in-the-middle.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:937e60cc99741c0d00f7c010ff5060e0d10fc6ac96e1a0860279f2fcc2771d54","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","targetId":"uc:UC-NET-07","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d79920ab398f4eb36290ae33669eac3cade6f8a36359da12af8b12118c6ec422","properties":{},"sourceDetailPath":"/data/v1/records/wf-c49-5eff4769.json","sourceId":"wf:C49","targetDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","targetId":"uc:UC-NET-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fd3514f74edfa41986374541285bf70869f4e608934ec75940a035723268b69e","properties":{"control_id":"SC-22","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-22-b1767165.json","targetId":"ctrl:nist-800-53:SC-22","type":"maps_to"}],"schemaVersion":1}
