← Compliance Blog

DEPENDENCY REVIEW / INTERNAL DNS

Make the dependency reviewable.

What relies on this service, who owns the risk, and what evidence supports the decision?

SBD Enterprise Services relies on internal name resolution. That gives the system owner a dependency to document: the services it supports, the people responsible for it, and the consequences of incorrect answers or loss of service.

Record the scope and owner

Place the two internal DNS services, their clients, and their administrative responsibilities in the boundary record. This is an air-gapped network. There is no external DNS forwarding or automated connection across the boundary; information enters or leaves through approved manual media transfers.

Name the service owner, identify who can approve changes, and keep the asset inventory and system description aligned. A reviewer should be able to follow the dependency without guessing what sits outside the diagram.

Explain the consequences

Ask the information owner which work would be affected by unavailable or incorrect name resolution. Record those consequences in the categorization analysis, alongside the system’s Moderate confidentiality, Low integrity, and Low availability impact levels.

The rationale needs to explain the actual mission impact. The number of servers alone cannot establish resilience or justify an impact level.

Connect the requirement to evidence

Record the requirements for service architecture and documented configurations. The full control selection record also needs the applicable requirements, enhancements, parameters, and responsible owners.

  • Boundary record: service scope, dependencies, and approved information flows.
  • Configuration evidence: the approved baseline, current state, collection date, and any deviations.
  • Assessment plan: the objectives, scope, and agreed procedures for checking required behavior.
  • Assessment report: expected and observed results, limitations, and any findings requiring action.

Keep the decision current

A new internal service or a change in DNS responsibilities can affect the dependency record. Use the Monitor step to review the change, update the evidence, and decide whether affected controls need reassessment. Escalate changes that alter the authorized scope or risk.