9.2: Use DNS Filtering Services
CSF v1.1 References:
PF v1.0 References:
Incorporates the following controls from the previous version: 7.7: Use of DNS Filtering Services, 12.3: Deny Communications With Known Malicious IP Addresses.
Control Statement
Use DNS filtering services on all enterprise assets to block access to known malicious domains.
[csf.tools Note: For more information on the Critical Security Controls, visit the Center for Internet Security.]