NIST 800-53 r5 · Controls catalogue · Family SC
SC-20Secure Name/Address Resolution Service (Authoritative Source)
Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.
Last updated: 21 August 2026 20:21 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (14)
- T1071 Application Layer Protocol Command And Control
- T1071.001 Web Protocols Command And Control
- T1071.002 File Transfer Protocols Command And Control
- T1071.003 Mail Protocols Command And Control
- T1071.004 DNS Command And Control
- T1553.004 Install Root Certificate Defense Impairment
- T1566 Phishing Initial Access
- T1566.001 Spearphishing Attachment Initial Access
- T1566.002 Spearphishing Link Initial Access
- T1568 Dynamic Resolution Command And Control
- T1568.002 Domain Generation Algorithms Command And Control
- T1598 Phishing for Information Reconnaissance
- T1598.002 Spearphishing Attachment Reconnaissance
- T1598.003 Spearphishing Link Reconnaissance
Weaknesses this control addresses (6)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-347 | Improper Verification of Cryptographic Signature | 900+ | Requires cryptographic signatures on authoritative data and support for verifying the chain of trust. |
CWE-345 | Insufficient Verification of Data Authenticity | 800+ | Mandates provision of authenticity and integrity artifacts that enable verification of name/address resolution data. |
CWE-346 | Origin Validation Error | 700+ | Enforces validation of the true origin of DNS responses via signatures and chain-of-trust mechanisms. |
CWE-290 | Authentication Bypass by Spoofing | 700+ | Directly counters DNS response spoofing by requiring cryptographic origin authentication artifacts from the authoritative source. |
CWE-940 | Improper Verification of Source of a Communication Channel | 56 | Provides the means to verify the source of name-resolution responses instead of relying on unauthenticated channels. |
CWE-353 | Missing Support for Integrity Check | 44 | Supplies the integrity-check artifacts (e.g., RRSIG, DNSKEY) that were previously missing for DNS responses. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-1490 UPD | 7.5 | 9.8 | 0.0116 | good |
CVE-2023-52235 UPD | 6.6 | 8.8 | 0.0052 | good |
CVE-2025-8036 UPD | 6.1 | 8.1 | 0.0042 | good |
CVE-2026-33002 | 5.6 | 7.5 | 0.0027 | good |
CVE-2025-61430 UPD | 5.0 | 6.5 | 0.0024 | good |
CVE-2026-36604 UPD | 5.0 | 6.5 | 0.0025 | good |
CVE-2026-75514 | 4.7 | 5.9 | 0.0046 | good |
CVE-2026-6874 | 3.6 | 4.3 | 0.0026 | good |
CVE-2024-53275 UPD | 3.5 | 5.3 | 0.0027 | good |
CVE-2025-59163 UPD | 1.5 | 2.1 | 0.0038 | good |
CVE-2026-12635 | 1.5 | 0.0 | 0.0016 | good |
CVE-2026-42559 UPD | 6.4 | 8.8 | 0.0021 | good |
CVE-2026-24281 UPD | 5.8 | 7.4 | 0.0063 | good |
CVE-2026-28271 | 5.1 | 6.5 | 0.0043 | good |
CVE-2026-46611 | 4.0 | 5.3 | 0.0012 | good |
CVE-2026-63118 | 3.5 | 6.9 | 0.0020 | good |
CVE-2026-55391 UPD | 5.3 | 7.5 | 0.0019 | good |
CVE-2025-24010 UPD | 5.0 | 6.5 | 0.0029 | good |
CVE-2025-59956 UPD | 5.1 | 6.5 | 0.0040 | good |
CVE-2024-42364 UPD | 5.0 | 6.5 | 0.0026 | good |
CVE-2022-22364 UPD | 4.5 | 5.3 | 0.0054 | good |