STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 10 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to STIGs

Infoblox NIOS 9.x Security Technical Implementation Guide

Version

V1R1

Release Date

Aug 14, 2026

SCAP Benchmark ID

Infoblox_NIOS_9-x_STIG

Total Checks

45

Tags

mobile
CAT I: 5CAT II: 40CAT III: 0

This Security Technical Implementation Guide is published as a tool to improve the security of Department of War (DoW) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (45)

V-285226MEDIUMInfoblox systems that perform zone transfers to non-Grid DNS service members must limit the number of concurrent sessions for zone transfers.V-285227MEDIUMThe Infoblox system must limit the number of concurrent client connections to the number of allowed dynamic update clients.V-285229HIGHThe Infoblox Grid Master must be configured as a stealth (hidden) domain DNS service member to protect the Zone Signing Key (ZSK) and Key Signing Key (KSK) residing on it.V-285237MEDIUMThe Infoblox system audit records must be backed up at least every seven days onto a different system or system component than the system or component being audited.V-285238MEDIUMThe Infoblox system must be configured to prohibit or restrict unapproved ports and protocols.V-285239MEDIUMThe Infoblox DNS service member must authenticate another DNS service member before establishing a remote and/or network connection using bidirectional authentication that is cryptographically based.V-285243MEDIUMThe Infoblox DNS service member must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.V-285244MEDIUMThe Infoblox DNS service member must provide additional data origin artifacts along with the authoritative data the system returns in response to external name/address resolution queries.V-285245MEDIUMThe Infoblox DNS service member implementation must provide the means to indicate the security status of child zones.V-285246MEDIUMThe validity period for the RRSIGs covering the DS RR for a zone's delegated children must be no less than two days and no more than one week.V-285247MEDIUMThe Infoblox DNS service member must enforce approved authorizations for controlling the flow of information between DNS servers and between DNS servers and DNS clients based on DNSSEC policies.V-285248MEDIUMThe Infoblox DNS service member must provide the means to enable verification of a chain of trust among parent and child domains (if the child supports secure resolution services).V-285249MEDIUMInfoblox DNS service members must protect the authenticity of communications sessions for dynamic updates.V-285253MEDIUMCNAME records must not point to a zone with lesser security for more than six months.V-285254MEDIUMThe Infoblox system must restrict the ability of individuals to use the DNS service member to launch denial-of-service (DoS) attacks against other information systems.V-285255MEDIUMThe Infoblox system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information-flooding types of denial-of-service (DoS) attacks.V-285259HIGHThe Infoblox DNS service member must have DNSSEC configured.V-285260MEDIUMThe Infoblox system must only allow the use of DoW PKI-established certificate authorities for verification of the establishment of protected transactions.V-285263MEDIUMAll authoritative name servers for a zone must be geographically disbursed.V-285264MEDIUMThe Infoblox system must prohibit recursion on external authoritative name servers.V-285265MEDIUMNSEC3 must be used for all external DNSSEC signed zones.V-285266MEDIUMAll authoritative DNS service members for a zone must be located on different network segments.V-285267MEDIUMThe Infoblox DNS service member implementation must maintain the integrity of information during reception.V-285269HIGHThe Infoblox NIOS must be the appropriate version.V-285271MEDIUMIn the event of a system failure, the Infoblox system must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to mission processes.V-285272MEDIUMIn the event of an error when validating the binding of another DNS servers identity to the DNS information, the Infoblox system must log the event and send notification to the DNS administrator.V-285273MEDIUMThe Infoblox DNS service member implementation must follow procedures to promote a secondary DNS service member to the role of primary DNS service member if the current primary DNS service member permanently loses functionality.V-285274HIGHThe Infoblox DNS service member must implement NIST FIPS-validated cryptography for provisioning digital signatures, generating cryptographic hashes, and protecting unclassified information requiring confidentiality.V-285276MEDIUMThe Infoblox DNS service member must be configured so that each DNS service member (NS) record in a zone file points to an active DNS service member authoritative for the domain specified in that record.V-285278MEDIUMAll authoritative DNS service members for a zone must have the same version of zone information.V-285279HIGHThe digital signature algorithm used for DNSSEC-enabled zones must be FIPS compatible.V-285280MEDIUMFor zones split between the external and internal sides of a network, the resource records (RRs) for the external hosts must be separate from the RRs for the internal hosts.V-285281MEDIUMIn a split DNS configuration, where separate DNS service members are used between the external and internal networks, the external DNS service member must be configured to not be reachable from inside resolvers.V-285282MEDIUMIn a split DNS configuration, where separate DNS service members are used between the external and internal networks, the internal DNS service member must be configured to not be reachable from outside resolvers.V-285283MEDIUMPrimary authoritative DNS service members must be configured to only receive zone transfer requests from specified secondary DNS service members.V-285284MEDIUMThe Infoblox DNS implementation must implement internal/external role separation.V-285285MEDIUMThe Infoblox DNS service member must use current and valid root DNS service members.V-285286MEDIUMThe Infoblox DNS service member must send outgoing DNS messages from a random port.V-285290MEDIUMThe Infoblox system must use a security policy that limits the propagation of access rights.V-285296MEDIUMThe Infoblox system must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.V-285297MEDIUMThe Infoblox system must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that the device meets organization-defined strength of mechanism requirements.V-285303MEDIUMThe Infoblox DNS server implementation must, for password-based authentication, require immediate selection of a new password upon account recovery.V-285304MEDIUMThe Infoblox DNS server implementation must, for password-based authentication, enforce organization-defined composition and complexity rules.V-285308MEDIUMThe Infoblox DNS Server must provide protected storage for cryptographic keys with origination-defined safeguards and/or hardware protected key store.V-285309MEDIUMThe Infoblox DNS member must synchronize system clocks within and between systems or system components.