adammontville / cis-controls-71-measures

0 stars 0 forks source link

Subcontrol 7.8 #89

Open adammontville opened 5 years ago

adammontville commented 5 years ago

To lower the chance of spoofed or modified emails from valid domains, implement Domain-based Message Authentication, Reporting and Conformance (DMARC) policy and verification, starting by implementing the Sender Policy Framework (SPF) and the Domain Keys Identified Mail (DKIM) standards.

Measures

None provided

Metrics

Boolean value = 1 if DMARC | SPF|DKIM is passed; otherwise 0
wmunyan commented 5 years ago

Inputs:

Assumption(s):

Operations:

Measures:

Metrics:

NOTE: Policy enforcement can be checked via Aggregate or Forensic DMARC reports and automation can be applied to these reports in order to alert administrators of DMARC/SPF/DKIM failures along with associated Source IPs and Domains.

https://en.wikipedia.org/wiki/DMARC https://en.wikipedia.org/wiki/Sender_Policy_Framework https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail