惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
人人都是产品经理
人人都是产品经理
博客园 - 三生石上(FineUI控件)
aimingoo的专栏
aimingoo的专栏
U
Unit 42
GbyAI
GbyAI
H
Help Net Security
A
Arctic Wolf
SecWiki News
SecWiki News
K
Kaspersky official blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
Blog — PlanetScale
Blog — PlanetScale
B
Blog
Spread Privacy
Spread Privacy
L
Lohrmann on Cybersecurity
C
Check Point Blog
O
OpenAI News
Microsoft Security Blog
Microsoft Security Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
Webroot Blog
Webroot Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Palo Alto Networks Blog
A
About on SuperTechFans
S
SegmentFault 最新的问题
Recent Announcements
Recent Announcements
S
Schneier on Security
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
Jina AI
Jina AI
The Hacker News
The Hacker News
V2EX - 技术
V2EX - 技术
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
腾讯CDC
罗磊的独立博客
G
GRAHAM CLULEY
L
LINUX DO - 热门话题
雷峰网
雷峰网
博客园 - 【当耐特】
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
美团技术团队
M
MIT News - Artificial intelligence
Engineering at Meta
Engineering at Meta
Hacker News: Ask HN
Hacker News: Ask HN
S
Security Affairs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客

Infoblox Blog

The Missing Link in the Anti-Scam Chain: Why DNS Belongs in the Room. (DNS, GASA, Global Anti-Scam Alliance, DNS Threat Intelligence) Oracle Cloud Discovery for Universal Asset Insights | Infoblox Why Asset Discovery Integrations Start with Network Intelligence Infoblox Kentik Acquisition: AI-Driven Network and Security Intelligence Proxyware actor behind fake 7-Zip is bigger than you think! Using Protective DNS to Dismantle Global Scam Networks | Infosecurity Europe 2026 Residential Proxies: Why DNS Is the Stronger Play Trusted Infrastructure Data for AI and AgenticOps | Infoblox Meet Your Security Analyst’s New AI Teammate | Infoblox IQ DCloud Uni-App: One Framework, 236,000+ Scam Sites Operation Endgame VS SocGholish Fake Updates Human Judgment Hacks: How Lookalike Domains Work Residential Proxies in the Wild Unlocking Universal DDI on Equinix: Infoblox Brings Cloud-First DDI to Equinix Network Edge “Headless”? What Is It and Do I Need to Go There? The Alert Is Already Too Late The Half of Your Attack Surface Nobody Owns Infoblox Earns Terraform Partner Premier Status for NIOS Provider What 550 Security Leaders Just Told Us about the Age of AI, and Why Preemptive Digital Risk Protection Can’t Wait Lookalike Domains Expose the iPhone Theft Economy Amusing Numerology: Analysis of the Numbers in Domain Names 4 Trends Shaping the Future of Network Operations Preemptive Threat Disruption at Scale: How Infoblox and Axur Turn External Risk into Protection Why the Axur Acquisition Marks a Turning Point for Preemptive Security Don’t Wait To Be Attacked: Stop Phishing, C2 and Data Exfiltration with Infoblox Threat Intelligence in AWS Network Firewall Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs AI, Project Glasswing and DNS: Beyond Vulnerabilities Three Infoblox Integrations with Google Cloud That Give Enterprise Teams More Control Over Their Networks Protective DNS: Why Telcos Are Turning to DNS as the Platform for Consumer Security Automating Infoblox DDI with Red Hat Ansible | Configuration as Code for DNS, DHCP and IPAM Hiding in Plain Sight: Abusing Composite Domain Names What You Cannot See is Hurting You Most NIST SP 800-81r3: A Long-Overdue Wake-Up Call for DNS Security Patterns, Pirates, and Provider Action: What We Learned Working with Keitaro NIST SP 800-81r3: What’s New? No Reach, No Risk: The Keitaro Abuse in Modern Cybercrime Distribution Unified Asset Visibility: A Strategic Imperative for CIOs and CISOs Infoblox Partners with Leading SASE Vendors to Modernize DNS and DHCP for Distributed Enterprises NIST DNS Security Best Practices: Top 5 Takeaways Break out the bubbly: NIST SP 800-81r3 has been published! Empowering Women to Lead in APJ: Infoblox at the Leadership Summit for Women in Technology, AI & Cyber
NIST Maps DNS Security to the Cybersecurity Framework 2.0
Titi Shodiya · 2026-07-01 · via Infoblox Blog

The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 is the most widely adopted cybersecurity framework in the world. Organizations across sectors and geographies use it to structure their security programs, report to boards and regulators, and benchmark their maturity. When something is mapped to CSF 2.0, it becomes visible to the people who make security decisions.

DNS security now has a formal place in the NIST CSF2.0.

The NIST recently finalized the mapping of Special Publication 800-81 Revision 3 (SP 800-81r3), the Secure DNS Deployment Guide, to the Cybersecurity Framework 2.0 through its National Online Informative References (OLIR) Program. This means that organizations using CSF 2.0 can now see, in NIST’s searchable catalog, exactly how DNS security controls map to the CSF outcomes they are working toward.

The OLIR mapping is the latest milestone in a sustained engagement with NIST and the global standards community. It follows the final publication of SP 800-81r3 in March 2026 and builds on Infoblox’s ongoing work with NIST on SP 800-53 control revisions, the National Cybersecurity Center of Excellence’s (NCCoE) AI agent identity and authorization project, and the NIST Cyber AI Profile.

What Is in the OLIR Mapping?

The NIST OLIR program provides a structured, standardized way to express relationships between cybersecurity documents. The SP 800-81r3 mapping connects DNS security guidance to the CSF 2.0 subcategories where DNS plays a direct role. For example:

  • Identify: SP 800-81r3’s guidance on DNS threat intelligence and DNS-based asset visibility maps to CSF 2.0 subcategories for risk assessment (ID.RA) and improvement (ID.IM).
  • Protect: Guidance on access control for DNS services, encrypted DNS and DNS hygiene maps to subcategories for identity management and access control (PR.AA), data security (PR.DS) and platform security (PR.PS).
  • Detect: Guidance on DNS logging, monitoring and integration with security information and event management (SIEM) platforms maps to subcategories for continuous monitoring (DE.CM) and adverse event analysis (DE.AE).
  • Respond: DNS-based incident response capabilities, including the ability to rapidly block malicious domains and attribute queries to specific devices, map to subcategories for incident management (RS.MA) and incident analysis (RS.AN).
  • Recover: DNS infrastructure resilience guidance, including redundancy, hybrid architectures and separation of duties, maps to subcategories for incident recovery plan execution (RC.RP).

The full mapping with section-level detail is available in the NIST OLIR catalog. It spans the three pillars of DNS security as defined in SP 800-81r3:

  1. Employing Protective DNS
  2. Protecting the DNS protocol
  3. Protecting the DNS service and infrastructure

Each of these pillars now has a formal, traceable connection to the CSF 2.0 that organizations already use to structure and assess their cybersecurity programs.

Why This Matters for Organizations

For CISOs and security teams, the OLIR mapping brings important clarity. DNS security has too often been overlooked—not for any lack of value, but because it has lacked an explicit place within the frameworks that security teams rely on. By formalizing this mapping, NIST has helped ensure that DNS security is properly recognized within CSF 2.0 and is now formally connected to the outcomes that security programs are already measured against. When an organization assesses its posture against CSF 2.0 subcategory DE.CM-01 (networks are monitored to find potentially adverse events), the OLIR catalog now points to SP 800-81r3’s guidance on DNS monitoring and logging as a recognized implementation path.

The operational case for DNS security is already well established. According to Anne Neuberger, then Deputy National Security Advisor, 92 percent of malware relies on DNS at some stage of its lifecycle. CISA’s own Protective DNS service blocked nearly 700 million connections from federal agencies to malicious domains between 2022 and 2023. What the OLIR mapping adds is the formal framework connection: the compliance and governance layer that allows organizations to translate that operational evidence into the CSF 2.0 assessments their boards and regulators expect.

For compliance and audit teams, the mapping provides auditable traceability. Organizations that demonstrate DNS security controls aligned with SP 800-81r3 can now reference the OLIR mapping as evidence of CSF 2.0 alignment. This is particularly relevant for organizations in regulated sectors, including financial services, healthcare, energy and government, where CSF 2.0 compliance is either required or strongly expected.

For procurement teams, the mapping provides a standards-based reference point for evaluating DNS security solutions. Requirements can be tied to specific CSF 2.0 subcategories, with SP 800-81r3 as the implementation guidance.

The Global Dimension

While NIST frameworks originate in the United States, their influence extends well beyond U.S. borders. CSF 2.0 is referenced or adopted by regulators and standards bodies in the European Union, the United Kingdom, Australia, New Zealand, Singapore, Malaysia, Thailand and across the broader Asia-Pacific region.

The European Union’s (EU) NIS2 Directive implementing guidance already references concepts aligned with CSF 2.0. The U.K.’s National Cyber Security Centre Cyber Assessment Framework shares structural similarities with CSF 2.0. Australia’s Essential Eight and the Protective Security Policy Framework reference NIST publications as part of their guidance ecosystem.

In Southeast Asia, where regulators in Singapore, Malaysia and Thailand align more closely with CSF 2.0 than with individual NIST special publications, the OLIR mapping provides a direct bridge between the framework they already reference and the DNS security implementation guidance they can now adopt.

For organizations operating across multiple regulatory environments, this provides a consistent, internationally recognized reference point for DNS security as a component of their cybersecurity program.

What to Do Next

For organizations using CSF 2.0 to structure their cybersecurity programs, we recommend the following:

  1. Review the OLIR mapping. The mapping is publicly available in the NIST OLIR catalog. Identify the CSF 2.0 subcategories where DNS security controls are relevant to your organization’s risk profile.
  2. Assess your DNS security posture. Use NIST SP 800-81r3 as the benchmark. Evaluate whether your organization employs Protective DNS, protects the DNS protocol (including encrypted DNS and DNSSEC) and maintains dedicated, resilient DNS infrastructure.
  3. Integrate DNS security into your CSF 2.0 reporting. If your organization reports against CSF 2.0, the OLIR mapping provides the formal basis to include DNS security controls in your assessment.
  4. Schedule a DNS Security Health Check. Infoblox offers DNS Security Health Checks and Workshops designed to help organizations evaluate their alignment with SP 800-81r3 and identify gaps.

Global Public Policy and Strategy Manager, Infoblox

Dr. Titi Shodiya holds a B.S. in Materials Science and Engineering with a minor in Mathematics from The Pennsylvania State University (2010), an M.S. in Electrical and Computer Engineering from Duke University (2012), and a Ph.D. in Mechanical Engineering and Materials Science from Duke University (2015). She completed a postdoctoral fellowship in Chemistry at the University of Michigan – Ann Arbor (2015–2017). Currently, Dr. Shodiya is a Global Public Policy and Strategy Manager at Infoblox since January 2025, where she advances U.S. and international public policy priorities related to DNS infrastructure and Internet security. Prior to joining the Infoblox team, Dr. Shodiya held a range of technical and leadership roles at the National Institute of Standards and Technology (NIST). 

View All Posts