In-region logging on Enterprise.Details
Secure Domains
Trust Center

GCC compliance mapping for DNS.

GCC regulators have moved from broad principles to specific technical controls, and much of that control surface runs through DNS. Select a framework to see each control, what it asks at the DNS layer, and how DNS Armor™ supports it.

Authority

National Cybersecurity Authority (NCA)

Current version

ECC-2:2024

Applies to

Government bodies, and organisations that own, operate or host Critical National Infrastructure. Four domains, 28 subdomains.

  • 2-5-3-7Protect

    What the framework asks at the DNS layer

    Security of Domain Name Service (DNS) — listed among the minimum requirements for network security management.

    What DNS Armor™ gives you to evidence it

    A protective resolver with DNSSEC validation and encrypted transport over DoH and DoT, enforced per tenant — cloud delivered, or on a Local Resolver appliance inside your own network.

  • 2-5-3-3Protect

    What the framework asks at the DNS layer

    Secure browsing and internet connectivity, including strict restrictions on suspicious websites, file storage and sharing websites, and remote access websites.

    What DNS Armor™ gives you to evidence it

    Web, application and content filtering by category, with Cloud Policies that activate on a schedule and Local Rulesets for explicit allow and block decisions.

  • 2-5-3-8Protect

    What the framework asks at the DNS layer

    Secure management and protection of the internet browsing channel against Advanced Persistent Threats, which normally use zero-day malware.

    What DNS Armor™ gives you to evidence it

    AI and behavioural detection of tunnelling, exfiltration and DGA activity that signature and reputation lists miss, on top of continuously updated threat, web-filtering and application feeds.

  • 2-4-3-5Resolve

    What the framework asks at the DNS layer

    Validation of the entity’s email service domains using SPF, DKIM and DMARC.

    What DNS Armor™ gives you to evidence it

    SPF, DKIM and DMARC are published as DNS records. Host those zones on DNS Armor Resolve™ with automated DNSSEC signing and KSK/ZSK rotation, and signing keys pinned to the region you choose.

  • 2-12-3-3 · 2-12-3-4Protect

    What the framework asks at the DNS layer

    Identify the SIEM techniques required for event-log collection, and monitor those logs continuously.

    What DNS Armor™ gives you to evidence it

    Three independent CEF streams from the Local Resolver Logs Connector — firewall events, query logs and portal audit logs — ingested natively by ArcSight, Microsoft Sentinel and Elastic, with onboarding templates for Splunk and QRadar.

  • 2-12-3-5Protect

    What the framework asks at the DNS layer

    Retain cybersecurity event logs for at least 12 months.

    What DNS Armor™ gives you to evidence it

    Your SIEM holds the 12-month record. DNS Armor™ query-log retention is an operational window — typically 30, 60 or 90 days — so this control is met by streaming the CEF feeds into your SIEM and retaining them there. That is precisely what the Logs Connector exists for.

  • —Platform

    What the framework asks at the DNS layer

    Govern who can change security configuration, and evidence the change history.

    What DNS Armor™ gives you to evidence it

    Nine RBAC roles with enforced separation of duties — at most one security, one licence and one DNS zone role per user — and every change recorded in Audit Logs.

How to use this mapping with your auditor

01

Treat each row as a starting point for your own control evidence, not as a certification. Your auditor assesses your controls; DNS Armor™ provides the technical capability and the logs.

02

Where a control needs retention beyond your query-log window, stream the CEF feeds into your SIEM and retain them there.

03

Framework versions are listed per framework. Ask us for the latest mapping before an audit if your regulator has issued an update.

Preparing for an audit?

Walk through the controls that apply to you with a solutions engineer.