01
Treat each row as a starting point for your own control evidence, not as a certification. Your auditor assesses your controls; DNS Armor™ provides the technical capability and the logs.
Authority
National Cybersecurity Authority (NCA)
Current version
ECC-2:2024
Applies to
Government bodies, and organisations that own, operate or host Critical National Infrastructure. Four domains, 28 subdomains.
What the framework asks at the DNS layer
Security of Domain Name Service (DNS) — listed among the minimum requirements for network security management.
What DNS Armor™ gives you to evidence it
A protective resolver with DNSSEC validation and encrypted transport over DoH and DoT, enforced per tenant — cloud delivered, or on a Local Resolver appliance inside your own network.
What the framework asks at the DNS layer
Secure browsing and internet connectivity, including strict restrictions on suspicious websites, file storage and sharing websites, and remote access websites.
What DNS Armor™ gives you to evidence it
Web, application and content filtering by category, with Cloud Policies that activate on a schedule and Local Rulesets for explicit allow and block decisions.
What the framework asks at the DNS layer
Secure management and protection of the internet browsing channel against Advanced Persistent Threats, which normally use zero-day malware.
What DNS Armor™ gives you to evidence it
AI and behavioural detection of tunnelling, exfiltration and DGA activity that signature and reputation lists miss, on top of continuously updated threat, web-filtering and application feeds.
What the framework asks at the DNS layer
Validation of the entity’s email service domains using SPF, DKIM and DMARC.
What DNS Armor™ gives you to evidence it
SPF, DKIM and DMARC are published as DNS records. Host those zones on DNS Armor Resolve™ with automated DNSSEC signing and KSK/ZSK rotation, and signing keys pinned to the region you choose.
What the framework asks at the DNS layer
Identify the SIEM techniques required for event-log collection, and monitor those logs continuously.
What DNS Armor™ gives you to evidence it
Three independent CEF streams from the Local Resolver Logs Connector — firewall events, query logs and portal audit logs — ingested natively by ArcSight, Microsoft Sentinel and Elastic, with onboarding templates for Splunk and QRadar.
What the framework asks at the DNS layer
Retain cybersecurity event logs for at least 12 months.
What DNS Armor™ gives you to evidence it
Your SIEM holds the 12-month record. DNS Armor™ query-log retention is an operational window — typically 30, 60 or 90 days — so this control is met by streaming the CEF feeds into your SIEM and retaining them there. That is precisely what the Logs Connector exists for.
What the framework asks at the DNS layer
Govern who can change security configuration, and evidence the change history.
What DNS Armor™ gives you to evidence it
Nine RBAC roles with enforced separation of duties — at most one security, one licence and one DNS zone role per user — and every change recorded in Audit Logs.
Treat each row as a starting point for your own control evidence, not as a certification. Your auditor assesses your controls; DNS Armor™ provides the technical capability and the logs.
Where a control needs retention beyond your query-log window, stream the CEF feeds into your SIEM and retain them there.
Framework versions are listed per framework. Ask us for the latest mapping before an audit if your regulator has issued an update.
Walk through the controls that apply to you with a solutions engineer.