SFC: DNS Registrar | Security Alliance — Security Checklist
Domain registration security, DNS configuration, access control, and monitoring.
1. Governance & Domain Management
-
Domain Security OwnerIs there a clearly designated person or team accountable for domain security?
-
Domain Inventory and DocumentationDo you maintain a complete, current record of all your domains and their configurations?
Notes:
2. Risk Assessment & Classification
-
Domain Classification and ComplianceDo you classify your domains by risk level and verify they meet the security requirements for their classification?
-
Enterprise Registrar Security RequirementsDo you use a registrar with enterprise-grade security for your critical domains?
Notes:
3. Access Control & Authentication
-
Registrar Access ControlDo you control and secure access to domain registrar and DNS management accounts?
-
Dedicated Domain Security Contact EmailIs your domain security contact email independent of the domains it protects?
-
Change Management for Domain OperationsDo you have change management procedures for critical domain operations?
Notes:
4. Technical Security Controls
-
DNS Security StandardsDo you enforce DNS security standards across all your domains?
-
Email Authentication StandardsDo you enforce email authentication standards and monitor for violations?
-
Domain Lock ImplementationDo you use domain locks to prevent unauthorized transfers and changes?
-
TLS Certificate Lifecycle ManagementDo you manage the full lifecycle of your TLS certificates?
Notes:
5. Monitoring & Detection
-
Domain and DNS MonitoringDo you monitor your domains for unauthorized changes to DNS records, registration status, and security settings?
-
Certificate Transparency MonitoringDo you monitor Certificate Transparency logs for unauthorized certificates issued for your domains?
-
Domain Expiration PreventionDo you actively prevent domain expiration?
Notes:
6. Incident Response
-
Alerting and Emergency ContactsDo you have alerting and emergency contacts in place for domain security incidents?
-
Domain Incident Response PlanDo you have an incident response plan for domain hijacking and DNS compromise?
Notes: