惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
宝玉的分享
宝玉的分享
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Engineering at Meta
Engineering at Meta
L
LangChain Blog
Jina AI
Jina AI
博客园 - 叶小钗
B
Blog RSS Feed
Recent Announcements
Recent Announcements
H
Help Net Security
小众软件
小众软件
大猫的无限游戏
大猫的无限游戏
B
Blog
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
D
DataBreaches.Net
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
罗磊的独立博客

Infoblox Blog

AI Agent Security: DNS-AID and Protective DNS | Infoblox Illegal Gambling Sites Reveal Three Types of Cybercrime Infoblox vNIOS on AWS China | Unified DDI Across Global and China Cloud Environments DNS-AID: Securing AI Agents and the Future of Agentic Commerce Modernizing Federal Networks Without Compromise | Infoblox DNS at IETF 126 To Open Weight or Not to Open Weight - That Should NOT be the question AI Governance with DNS Security | Infoblox Infoblox Supports the Next Generation of Cybersecurity Talent at Cyber Battle Australia The Second Life of Expired Domains Illegal Streaming Fronts a $7M Dropcatch Domain Operation Expired Malicious Domains Bring New Threats to Life How Many AI Agents Are Running in Your Organization? Infoblox IQ for DDI Is Now Generally Available | AI for Network Operations Kentik Joins Infoblox: Network Observability & AI Cybercrime Trends and Threat Intelligence | Infoblox AI’s First Move Is a Name Lookup External Attack Surface Management: See What Attackers See | Infoblox FedRAMP DDI Management with Infoblox Government Cloud Inside a Global Procurement-Themed AiTM Phishing Campaign The Missing Link in the Anti-Scam Chain: Why DNS Belongs in the Room. (DNS, GASA, Global Anti-Scam Alliance, DNS Threat Intelligence) Oracle Cloud Discovery for Universal Asset Insights | Infoblox Why Asset Discovery Integrations Start with Network Intelligence Infoblox Kentik Acquisition: AI-Driven Network and Security Intelligence Proxyware actor behind fake 7-Zip is bigger than you think! Using Protective DNS to Dismantle Global Scam Networks | Infosecurity Europe 2026 Residential Proxies: Why DNS Is the Stronger Play Trusted Infrastructure Data for AI and AgenticOps | Infoblox Meet Your Security Analyst’s New AI Teammate | Infoblox IQ DCloud Uni-App: One Framework, 236,000+ Scam Sites
NIST Maps DNS Security to the Cybersecurity Framework 2.0
Titi Shodiya · 2026-07-01 · via Infoblox Blog

The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 is the most widely adopted cybersecurity framework in the world. Organizations across sectors and geographies use it to structure their security programs, report to boards and regulators, and benchmark their maturity. When something is mapped to CSF 2.0, it becomes visible to the people who make security decisions.

DNS security now has a formal place in the NIST CSF2.0.

The NIST recently finalized the mapping of Special Publication 800-81 Revision 3 (SP 800-81r3), the Secure DNS Deployment Guide, to the Cybersecurity Framework 2.0 through its National Online Informative References (OLIR) Program. This means that organizations using CSF 2.0 can now see, in NIST’s searchable catalog, exactly how DNS security controls map to the CSF outcomes they are working toward.

The OLIR mapping is the latest milestone in a sustained engagement with NIST and the global standards community. It follows the final publication of SP 800-81r3 in March 2026 and builds on Infoblox’s ongoing work with NIST on SP 800-53 control revisions, the National Cybersecurity Center of Excellence’s (NCCoE) AI agent identity and authorization project, and the NIST Cyber AI Profile.

What Is in the OLIR Mapping?

The NIST OLIR program provides a structured, standardized way to express relationships between cybersecurity documents. The SP 800-81r3 mapping connects DNS security guidance to the CSF 2.0 subcategories where DNS plays a direct role. For example:

  • Identify: SP 800-81r3’s guidance on DNS threat intelligence and DNS-based asset visibility maps to CSF 2.0 subcategories for risk assessment (ID.RA) and improvement (ID.IM).
  • Protect: Guidance on access control for DNS services, encrypted DNS and DNS hygiene maps to subcategories for identity management and access control (PR.AA), data security (PR.DS) and platform security (PR.PS).
  • Detect: Guidance on DNS logging, monitoring and integration with security information and event management (SIEM) platforms maps to subcategories for continuous monitoring (DE.CM) and adverse event analysis (DE.AE).
  • Respond: DNS-based incident response capabilities, including the ability to rapidly block malicious domains and attribute queries to specific devices, map to subcategories for incident management (RS.MA) and incident analysis (RS.AN).
  • Recover: DNS infrastructure resilience guidance, including redundancy, hybrid architectures and separation of duties, maps to subcategories for incident recovery plan execution (RC.RP).

The full mapping with section-level detail is available in the NIST OLIR catalog. It spans the three pillars of DNS security as defined in SP 800-81r3:

  1. Employing Protective DNS
  2. Protecting the DNS protocol
  3. Protecting the DNS service and infrastructure

Each of these pillars now has a formal, traceable connection to the CSF 2.0 that organizations already use to structure and assess their cybersecurity programs.

Why This Matters for Organizations

For CISOs and security teams, the OLIR mapping brings important clarity. DNS security has too often been overlooked—not for any lack of value, but because it has lacked an explicit place within the frameworks that security teams rely on. By formalizing this mapping, NIST has helped ensure that DNS security is properly recognized within CSF 2.0 and is now formally connected to the outcomes that security programs are already measured against. When an organization assesses its posture against CSF 2.0 subcategory DE.CM-01 (networks are monitored to find potentially adverse events), the OLIR catalog now points to SP 800-81r3’s guidance on DNS monitoring and logging as a recognized implementation path.

The operational case for DNS security is already well established. According to Anne Neuberger, then Deputy National Security Advisor, 92 percent of malware relies on DNS at some stage of its lifecycle. CISA’s own Protective DNS service blocked nearly 700 million connections from federal agencies to malicious domains between 2022 and 2023. What the OLIR mapping adds is the formal framework connection: the compliance and governance layer that allows organizations to translate that operational evidence into the CSF 2.0 assessments their boards and regulators expect.

For compliance and audit teams, the mapping provides auditable traceability. Organizations that demonstrate DNS security controls aligned with SP 800-81r3 can now reference the OLIR mapping as evidence of CSF 2.0 alignment. This is particularly relevant for organizations in regulated sectors, including financial services, healthcare, energy and government, where CSF 2.0 compliance is either required or strongly expected.

For procurement teams, the mapping provides a standards-based reference point for evaluating DNS security solutions. Requirements can be tied to specific CSF 2.0 subcategories, with SP 800-81r3 as the implementation guidance.

The Global Dimension

While NIST frameworks originate in the United States, their influence extends well beyond U.S. borders. CSF 2.0 is referenced or adopted by regulators and standards bodies in the European Union, the United Kingdom, Australia, New Zealand, Singapore, Malaysia, Thailand and across the broader Asia-Pacific region.

The European Union’s (EU) NIS2 Directive implementing guidance already references concepts aligned with CSF 2.0. The U.K.’s National Cyber Security Centre Cyber Assessment Framework shares structural similarities with CSF 2.0. Australia’s Essential Eight and the Protective Security Policy Framework reference NIST publications as part of their guidance ecosystem.

In Southeast Asia, where regulators in Singapore, Malaysia and Thailand align more closely with CSF 2.0 than with individual NIST special publications, the OLIR mapping provides a direct bridge between the framework they already reference and the DNS security implementation guidance they can now adopt.

For organizations operating across multiple regulatory environments, this provides a consistent, internationally recognized reference point for DNS security as a component of their cybersecurity program.

What to Do Next

For organizations using CSF 2.0 to structure their cybersecurity programs, we recommend the following:

  1. Review the OLIR mapping. The mapping is publicly available in the NIST OLIR catalog. Identify the CSF 2.0 subcategories where DNS security controls are relevant to your organization’s risk profile.
  2. Assess your DNS security posture. Use NIST SP 800-81r3 as the benchmark. Evaluate whether your organization employs Protective DNS, protects the DNS protocol (including encrypted DNS and DNSSEC) and maintains dedicated, resilient DNS infrastructure.
  3. Integrate DNS security into your CSF 2.0 reporting. If your organization reports against CSF 2.0, the OLIR mapping provides the formal basis to include DNS security controls in your assessment.
  4. Schedule a DNS Security Health Check. Infoblox offers DNS Security Health Checks and Workshops designed to help organizations evaluate their alignment with SP 800-81r3 and identify gaps.

Global Public Policy and Strategy Manager, Infoblox

Dr. Titi Shodiya holds a B.S. in Materials Science and Engineering with a minor in Mathematics from The Pennsylvania State University (2010), an M.S. in Electrical and Computer Engineering from Duke University (2012), and a Ph.D. in Mechanical Engineering and Materials Science from Duke University (2015). She completed a postdoctoral fellowship in Chemistry at the University of Michigan – Ann Arbor (2015–2017). Currently, Dr. Shodiya is a Global Public Policy and Strategy Manager at Infoblox since January 2025, where she advances U.S. and international public policy priorities related to DNS infrastructure and Internet security. Prior to joining the Infoblox team, Dr. Shodiya held a range of technical and leadership roles at the National Institute of Standards and Technology (NIST). 

View All Posts