DNSMentor

Runbooks

Produce DNS evidence for an audit

25 min to do · 3 related

How do I evidence DNS change control for ISO 27001 or Cyber Essentials?

Export the audit trail for the period and scope in question, export the training compliance report showing who was competent to make those changes, and show the approval policy that was in force. Assessors ask for three things — that changes were authorised, recorded, and made by someone competent — and DNSMentor produces all three as a by-product.

DNS is a recurring finding in security assessments precisely because most MSPs cannot evidence it. Everything else has a ticket; DNS has a line in one saying "DNS updated".

# What an assessor actually asks

QuestionWhat satisfies itWhere it comes from
Are changes authorised?Approval policy plus records of approvals given, by a person who is not the author.Admin → Approval policy, Audit trail
Are changes recorded?A complete, tamper-evident log of what changed, when and by whom.Audit → Export
Was the person competent?Training records tying the engineer to demonstrated skill at the time.Admin → Reports
Can you detect tampering?Hash-chained entries and a verification result.Audit → Verify chain
Is access controlled?Roles, SSO and offboarding evidence.Admin → Users & roles

# Producing the pack

  1. Scope it Filter the audit trail by client and date range. An assessor wants the scope they asked about, not everything you have.
  2. Run chain verification and include the result A trail that says it is intact is stronger than one that merely exists, and it is the part most tooling cannot produce.
  3. Export the training compliance report It ties each engineer to the modules they completed and when they reached each skill level.
  4. Screenshot the approval policy Policy is a configuration, so evidence it as it stands and note the date.
This works per client too

The same export scoped to one client answers a customer security questionnaire, which is increasingly what wins the larger accounts.

Was this helpful?

Related

Still stuck?

Raise a ticket from inside the platform and your tenant, plan and recent activity come attached automatically. A client currently offline is treated as urgent on every plan.

Last updated