PlumbTrackLive demoGRC Risk System

← control library

Secure Name/Address Resolution Service (Authoritative Source) SC-20

System and Communications Protection · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SC-20 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, System and Communications Protection family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SC-20 (Secure Name/Address Resolution Service — Authoritative Source) applies when your server answers DNS (Domain Name System) queries as the authority for a zone. DNS is the service that turns names like example.com into network addresses. This control says: when you hand out those answers, also hand out proof that each answer is genuine and unaltered, and make it possible to verify a chain of trust from a parent domain down to its child zones. In practice that means signing your zone with DNSSEC (Domain Name System Security Extensions), which adds cryptographic signatures to DNS answers. It is a Low-baseline control.

What good looks like

Framework mapping

How to move it toward Implemented