Securely Authenticate Dynamic Updates (Scored)
Scanned 9/3/2026
Install to Claude Code
npx -y skills add CyberStrikeus/CyberStrike --skill cis-bind9-v301-5-2 --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cis Bind9 V301 5 2?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-bind9-v301-5-2)More formats (shields.io, HTML) on the badges page.
---
name: cis-bind9-v301-5-2
description: "Securely Authenticate Dynamic Updates (Scored)"
category: cis-bind
version: "3.0.1"
author: cyberstrike-official
tags: [cis, bind, dns, isc-bind, bind9, zone-transfers]
cis_id: "5.2"
cis_benchmark: "CIS ISC BIND DNS Server 9.9 Benchmark v3.0.1"
tech_stack: [bind, isc-bind, dns, linux]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---
# CIS 5.2 — Securely Authenticate Dynamic Updates
## Profile Applicability
- Level 1 - Authoritative Name Server
## Description
Dynamic updates are used to automate the updating of zones. Dynamic updates are typically used with DHCP; however, updates may include other records. The allow-update option allows deleting or adding any resource records of a zone except the SOA and NS records, and should not be used. Instead the update-policy option allows a more granular policy to be specified so that only specific resource record types and a specific sub-domain may be updated. The update-policy must be securely authenticated with a key identifier, rather than by an IP address. The key identifier may specify a `TSIG` key, a `GSS-TSIG` key, or a `SIG(0)` key.
## Rationale
Allowing other systems to make permanent updates to your zones is of course not allowed by default, and needs to be carefully secured. Consider the power of an attack that could update the zone to direct clients and servers to the malicious server of the attacker's choice. The attack would not be restricted to just HTTP, but every connection and protocol that uses a name and allows weak authentication may be subject to redirection and a variety of man-in-the-middle and protocol downgrade attacks. Therefore, it is important that all dynamic updates be securely authenticated using a cryptographic key, and not rely on an IP address.
## Impact
None noted.
## Audit Procedure
Perform the following steps:
- Search for the allow-update option in all of the included configuration files, and in the zone files. If any allow-update options are present, other than `none` or `localhost`, as shown below, then the configuration is not compliant.
```bash
# grep allow-update $CONFIG_FILES $ZONE_FILES
/etc/named.conf: allow-update { none; };
/. . . /data/cisecurity.org: allow-update { "localhost"; };
```
- Search for any update-policy options in all of the zone files. Any update policies found, should not contain any IP addresses, network CIDR notations, or any ACL names that represents an IP addresses. The only entries in the update-policy should be key identifiers or `local` as shown below. All of the following are compliant.
```bash
# grep update-policy $ZONE_FILES
/. . ./data/internal.org: update-policy { grant ns1-dhcp-update-key name dyn.internal.org A; };
/. . ./data/cisecurity.local: update-policy { grant dyn_update_key self office.cisecurity.local A; };
/. . ./data/test.local: update-policy { local; };
```
## Remediation
Perform the following steps for remediation:
- Remove any `allow-update` options from the global options configuration.
- Replace or add `allow-update` options to the zone files to specify a securely generated `TSIG` or `SIG(0)` key identifier, along with the appropriate domain or sub-domain, and the appropriate resource record type.
## Default Value
Dynamic updates are not allowed by default.
## References
None listed.
## CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
| ---------------- | -------------------------------------------------------------------- | ---- | ---- | ---- |
| v6 | 9 - Limitation and Control of Network Ports, Protocols, and Services | Y | Y | Y |
## MITRE ATT&CK Mappings
| Tactic | Technique |
| ------ | ----------------------------------------- |
| Impact | T1565 - Data Manipulation |
| Impact | T1565.002 - Transmitted Data Manipulation |
## Profile
- Level 1 - Authoritative Name Server
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!