GCP-Network-DNSSEC-disable-on-cloud-DNS
Severity: High
Description: This control ensures that DNSSEC is enabled for Public Cloud DNS. Domain Name System Security Extensions (DNSSEC) in Cloud DNS enables domain owners to take easy steps to protect their domains against DNS hijacking and man-in-the-middle and other attacks.
Remediation Steps:
Perform following to set host maintenance migrate option :
Sign in to GCP Console https://console.cloud.google.com.
Go to Cloud DNS in GCP Console by visiting net-service/dns/zones
Click on the affected Cloud DNS from the list.
Click on Edit option.
Turn ON the DNSSEC setting.
Click on SAVE button.
Important:
Reference:
CIS Google Cloud Platform Foundation Benchmark v1.2.0 - 05-01-2021: Recommendation #3.3
Â
Blue Hexagon Proprietary