Malware often exploits Domain Name Service (DNS) vulnerabilities to redirect network traffic to malicious websites. Due to security risks to entities on the state network, it is imperative to minimize the threat to state network DNS traffic. By requiring DNS queries to utilize trusted DNS resolvers to identify and locate computer systems and resources on the Internet, exposure to the risk of system compromise is minimized.
This standard statement applies to all state agencies, boards, commissions, and administrative sections of institutions of higher education whose traffic crosses the state network destined for the Internet.
Arkansas Code Ann. Sections 25-4-105(a)(2)(M) and 25-4-105(a)(2)(0) gives the Department of Information Systems the authority to define standards, policies and specifications for state agencies and ensuring agencies' compliance with those policies, procedures and standards. In addition, the department develops information technology security policy for state agencies. The State Security Working Group, made up of representatives of state agencies and higher education, wrote the Domain Name Service Standard.
The State Cyber Security Office reserves the right to audit for compliance with this standard. Furthermore, the State Cyber Security Office has the right to grant an exception or exclusion to any part of this standard. The Arkansas Division of Legislative Audit also audits for compliance with this standard.
Date | Description of Change |
6/13/2012 | Original Standard Statement Published |
http://technet.microsoft.com/enus/library/cc758341(WS. 10).aspx
Direct inquiries about this standard to:
Department of Information Systems
State Cyber Security Office
One Capitol Mall
Little Rock, Arkansas 72201
Phone: 501-682-2701
FAX: 501-682-4310
Email: itpolicyteam@arkansas.gov
DIS standards, policies and best practices can be found on the Internet at: http://www.dis.arkansas.gov/policiesStandards/Pages/default.aspx
169.00.12 Ark. Code R. 001