{"id":10888,"date":"2025-01-16T06:35:00","date_gmt":"2025-01-16T14:35:00","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=10888"},"modified":"2025-06-11T16:48:40","modified_gmt":"2025-06-11T23:48:40","slug":"the-white-house-executive-order-requiring-dns-as-a-frontline-security-control","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/","title":{"rendered":"The White House Executive Order: Requiring DNS as a Frontline Security Control"},"content":{"rendered":"<p>Building on the January Executive Order (EO) addressed below, the White House issued a June EO that also directs federal Executive branch agencies to implement TLS 1.3, or successor(s), by 2030, in part to establish the base layer for future PQC efforts. While this action is mandated to the Executive branch, all branches and tiers of government including SLTT, and critical infrastructure sectors should treat the mandate as applicable. Protective DNS with DNS-over-TLS will continue to protect the government&#8217;s information protection efforts, reduces the attack surface, and contains threats by securing communications channels.<\/p>\n<p>On January 16, 2025, the White House issued a comprehensive Executive Order (EO) aimed at strengthening and promoting the Nation\u2019s cybersecurity. The EO includes specific measures to:<\/p>\n<ul class=\"list-spacing\">\n<li>Improve accountability for software and cloud service providers<\/li>\n<li>Strengthen the security of Federal communications and identity management systems<\/li>\n<li>Promote innovative developments and the use of emerging technologies for cybersecurity across executive departments and agencies<\/li>\n<\/ul>\n<p>Noteworthy among the key measures introduced is the requirement for encrypted DNS protocols that ensure the confidentiality and integrity of DNS traffic. This recognizes <strong>DNS as a critical frontline security control<\/strong>, emphasizing its significance in cybersecurity defense-in-depth strategy. <\/p>\n<h3>Why Encrypted DNS Matters<\/h3>\n<p>DNS is often referred to as \u201cthe phonebook of the internet,\u201d translating human-readable domain names into IP addresses. The original intent of DNS was to distribute information such as host and IP address mappings, mail routing information, etc., so it has not traditionally been viewed as a tool for securing network communications. However, the role DNS plays in enabling nearly all network communications today makes it an effective tool for not only monitoring but also for managing those communications. Encrypted DNS provides one such mechanism for DNS to serve as a security control.<\/p>\n<p>Traditional DNS queries are transmitted in plaintext, making them vulnerable to interception and manipulation. Encrypting DNS traffic (through protocols such as DNS over HTTPS (DoH) and DNS over TLS (DoT)) enhances security by: <\/p>\n<ol class=\"list-spacing\">\n<li><strong>Protecting Confidentiality<\/strong>: Ensuring that DNS queries cannot be intercepted and used to monitor users\u2019 browsing activities.<\/li>\n<li><strong>Preserving Integrity<\/strong>: Preventing malicious actors from redirecting users to fraudulent websites via DNS spoofing.<\/li>\n<\/ol>\n<p>This requirement builds upon the requirements set forth in the prior <strong><a href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2022\/01\/M-22-09.pdf\" target=\"_blank\">Office of Management and Budget\u2019s (OMB) Memorandum M-22-09<\/a><\/strong> and <strong><a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2024-05\/Encrypted%20DNS%20Implementation%20Guidance_508c.pdf\" target=\"_blank\">CISA&#8217;s Encrypted DNS Implementation Guide<\/a><\/strong>, which requires the federal Civilian Executive Branch (FCEB) agencies\u2019 DNS infrastructure to support the use of encrypted DNS when communicating with agency endpoints, wherever technically supported. <\/p>\n<h3>Key Requirements on Encrypted DNS under the EO<\/h3>\n<p>The specific requirements for encrypted DNS are as follows:<\/p>\n<ol class=\"list-spacing\">\n<li>Within 90 days, the Secretary of Homeland Security, acting through the Director of CISA, will draft template contract language requiring any DNS resolver (whether client or server) used by federal agencies to support encrypted DNS. This language will be submitted to the Federal Acquisition Regulation (FAR) Council, which has 120 days to review and take steps to amend the FAR.<\/li>\n<li>FCEB agencies are required to enable encrypted DNS protocols:\n<ul class=\"list-spacing\" style=\"margin-top: 20px;\">\n<li style=\"list-style-type: disc;\">On existing clients and servers that support these protocols within 180 days; and<\/li>\n<li style=\"list-style-type: disc;\">On additional clients and servers supporting such protocols within 180 days.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h3>Challenges and Opportunities<\/h3>\n<p>Encrypted DNS requires additional computing resources particularly on DNS servers, because of the need to perform encryption and decryption when sending and receiving DNS messages. Agencies should anticipate this and ensure that their DNS servers have sufficient resources to handle the query load before beginning any widespread deployment of encrypted DNS. Failure to properly implement encrypted DNS could bring down the entire networks, along with their applications and users.<\/p>\n<p>The use of encrypted DNS may also make troubleshooting more difficult because IT staff using network troubleshooting tools won\u2019t have ready access to the contents of DNS queries or responses. The contents of DNS queries and responses will still be available to IT staff on the name servers themselves, of course, because those name servers will have performed the requisite decryption.<\/p>\n<p>However, the benefit of encrypted DNS outweighs these challenges.  <\/p>\n<p>To overcome these challenges and ensure cyber resiliency, agencies and organizations should limit the co-existence of multiple mission-critical services on a single system. This separation of duties will ensure the highest possible resilience, given the increased computational requirements. The infrastructure hosting the DNS service should be dedicated to that task and hardened for this purpose to reduce the attack surface and ensure that adequate system resources are available to the DNS service. The infrastructure should include sufficient capacity for elements of the DNS service such as logging, support of encrypted DNS protocols and Protective DNS, where applicable. This may be easier to accomplish on purpose-built DNS services, either as-a-service or via virtual or physical appliances.<\/p>\n<h3>Implications for Federal Agencies<\/h3>\n<p>As agencies move forward with these initiatives, it is essential to stay informed about the latest technological advancements and adopt best practices, including:<\/p>\n<ul class=\"list-spacing\">\n<li>Auditing their existing DNS infrastructure to evaluate the health and configuration of the servers and clients to ensure they are optimized to support encrypted DNS protocols<\/li>\n<li>Planning and executing the implementation of these protocols across their networks for both external and internal DNS servers<\/li>\n<li>Collaborating with vendors and service providers to ensure compliance with the new requirements<\/li>\n<\/ul>\n<h3>How Infoblox Can Help<\/h3>\n<p>As a leader in secure DNS solutions, Infoblox is uniquely positioned to assist federal agencies in meeting these new requirements. Our solutions are:<\/p>\n<ul class=\"list-spacing\">\n<li><strong>Comprehensive<\/strong>: Support for DoH, DoT and advanced threat intelligence for both internal and external DNS servers that are on-premises, in the cloud or a combination thereof<\/li>\n<li><strong>Scalable<\/strong>: Ensuring agencies can deploy encrypted DNS protocols across large and complex networks<\/li>\n<li><strong>Easy to Deploy<\/strong>: Simplifying the transition to encrypted DNS with minimal disruption<\/li>\n<\/ul>\n<h3>Takeaway<\/h3>\n<p>This Executive Order marks an important step in the fight against cybercrime targeting DNS infrastructure. By mandating encrypted DNS, the federal government is setting a high standard for cybersecurity resilience, with ripple effects expected across industries. Infoblox is proud to support this mission, delivering the tools and expertise necessary to secure the foundation of the internet.  <\/p>\n<h3>For Additional Information<\/h3>\n<p>For more information on how Infoblox can help your organization implement encrypted DNS, visit our <strong><a href=\"https:\/\/blogs.infoblox.com\/security\/implementing-cisas-encrypted-dns-guidance-what-it-means-for-federal-agencies\/\">blog<\/a><\/strong> or contact us at <a href=\"https:\/\/info.infoblox.com\/contact-form\/\" target=\"_blank\"><strong>https:\/\/info.infoblox.com\/contact-form\/<\/strong><\/a>.<\/p>\n<p>Agencies should contact the Infoblox team at <a href=\"mailto:scsprogram@infobloxfederal.com\" target=\"_blank\"><strong>scsprogram@infobloxfederal.com<\/strong><\/a> or their account representatives directly for additional information.<\/p>\n<p>To learn more about Trinzic X6:<br \/>\n<a href=\"https:\/\/www.infoblox.com\/products\/infoblox-appliances\/\" target=\"_blank\"><strong>https:\/\/www.infoblox.com\/products\/infoblox-appliances\/<\/strong><\/a><\/p>\n<p>To learn more about Advanced DNS Protection (ADP) that support DoT and DoH:<br \/>\n<a href=\"https:\/\/www.infoblox.com\/products\/advanced-dns-protection\/\" target=\"_blank\"><strong>https:\/\/www.infoblox.com\/products\/advanced-dns-protection\/<\/strong><\/a><\/p>\n<p>To learn more about Infoblox\u2019s threat intelligence:<br \/>\n<a href=\"https:\/\/www.infoblox.com\/threat-intel\/\" target=\"_blank\"><strong>https:\/\/www.infoblox.com\/threat-intel\/<\/strong><\/a><\/p>\n<p>To learn more about Infoblox Threat Defense:<br \/>\n<a href=\"https:\/\/www.infoblox.com\/products\/threat-defense\/\" target=\"_blank\"><strong>https:\/\/www.infoblox.com\/products\/threat-defense\/<\/strong><\/a><\/p>\n<p>To learn more about Infoblox\u2019s Cyber Security Ecosystem:<br \/>\n<a href=\"https:\/\/www.infoblox.com\/solutions\/security-ecosystem\/\" target=\"_blank\"><strong>https:\/\/www.infoblox.com\/solutions\/security-ecosystem\/<\/strong><\/a><\/p>\n<p>To learn more about the White House press release on the new EO: <a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2025\/01\/16\/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity\/\" target=\"_blank\"><strong>https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2025\/01\/16\/executive-order-on-strengthening-and-promoting-innovation-in-the-nations-cybersecurity\/<\/strong><\/a><\/p>\n<style>\n.code-format {\n\tfont-family: 'Courier New';\n}\n.image-caption {\n    font-size: 12px;\n}\n.list-spacing li{margin-bottom:20px}\nol.list-spacing > li::marker {\n    font-weight: 700;\n}\n<\/style>\n<p><script>\njQuery('.single h1').html('<span class=\"gradient\">The White House Executive Order<\/span>: Requiring DNS as a Frontline Security Control');\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Building on the January Executive Order (EO) addressed below, the White House issued a June EO that also directs federal Executive branch agencies to implement TLS 1.3, or successor(s), by 2030, in part to establish the base layer for future PQC efforts. While this action is mandated to the Executive branch, all branches and tiers [&hellip;]<\/p>\n","protected":false},"author":182,"featured_media":10890,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[2],"tags":[1137,412,360,96,870,413,252,1138,16,1139,1140],"class_list":{"0":"post-10888","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security","8":"tag-executive-order","9":"tag-encrypted-dns","10":"tag-dns-security","11":"tag-infoblox-adp","12":"tag-defense-in-depth","13":"tag-dot","14":"tag-doh","15":"tag-cybersecurity-compliance","16":"tag-infoblox","17":"tag-cisa-guidance","18":"tag-white-house","19":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The White House Executive Order: Requiring DNS as a Frontline Security Control<\/title>\n<meta name=\"description\" content=\"Today, the White House issued a comprehensive Executive Order aimed at strengthening and promoting the Nation&#039;s cybersecurity. Among the key measures is the requirement of encrypted DNS protocols for federal agencies.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The White House Executive Order: Requiring DNS as a Frontline Security Control\" \/>\n<meta property=\"og:description\" content=\"Today, the White House issued a comprehensive Executive Order aimed at strengthening and promoting the Nation&#039;s cybersecurity. Among the key measures is the requirement of encrypted DNS protocols for federal agencies.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-01-16T14:35:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-11T23:48:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"448\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Dave Signori\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"The White House Executive Order: Requiring DNS as a Frontline Security Control\" \/>\n<meta name=\"twitter:description\" content=\"Today, the White House issued a comprehensive Executive Order aimed at strengthening and promoting the Nation&#039;s cybersecurity. Among the key measures is the requirement of encrypted DNS protocols for federal agencies.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Dave Signori\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/\"},\"author\":{\"name\":\"Dave Signori\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/ce77af4c19aba94f344e3004644ae65e\"},\"headline\":\"The White House Executive Order: Requiring DNS as a Frontline Security Control\",\"datePublished\":\"2025-01-16T14:35:00+00:00\",\"dateModified\":\"2025-06-11T23:48:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/\"},\"wordCount\":1138,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg\",\"keywords\":[\"Executive Order\",\"Encrypted DNS\",\"DNS Security\",\"Infoblox ADP\",\"Defense-in-Depth\",\"DoT\",\"DoH\",\"cybersecurity compliance\",\"Infoblox\",\"CISA Guidance\",\"White House\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/\",\"name\":\"The White House Executive Order: Requiring DNS as a Frontline Security Control\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg\",\"datePublished\":\"2025-01-16T14:35:00+00:00\",\"dateModified\":\"2025-06-11T23:48:40+00:00\",\"description\":\"Today, the White House issued a comprehensive Executive Order aimed at strengthening and promoting the Nation's cybersecurity. Among the key measures is the requirement of encrypted DNS protocols for federal agencies.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg\",\"width\":800,\"height\":448},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"The White House Executive Order: Requiring DNS as a Frontline Security Control\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/ce77af4c19aba94f344e3004644ae65e\",\"name\":\"Dave Signori\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/wp-content\\\/uploads\\\/avatar_user_182_1571851798-96x96.jpg\",\"url\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/wp-content\\\/uploads\\\/avatar_user_182_1571851798-96x96.jpg\",\"contentUrl\":\"https:\\\/\\\/live-infoblox-blog.pantheonsite.io\\\/wp-content\\\/uploads\\\/avatar_user_182_1571851798-96x96.jpg\",\"caption\":\"Dave Signori\"},\"description\":\"VP of product management at Infoblox, the global leader in DNS, DHCP, and IP Address Management (DDI) supporting these services in 350 of the Fortune 500. Product management responsibilities for the Core DDI and network automation product lines. This includes DDI as well as discovery, hybrid cloud, traffic management, Microsoft management, analytics and NetMRI. Founding member of two successful start-ups including Emprisa Networks where as CTO held engineering, product management, pre-sales and professional services responsibilities. After Emprisa was acquired by BMC Software in 2007, stayed on at BMC as a director in product management for network automation, cloud life cycle management, and orchestration. Spends free time with family, travel, and playing in a classic rock \u2018dad\u2019 band.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/dave-signori\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The White House Executive Order: Requiring DNS as a Frontline Security Control","description":"Today, the White House issued a comprehensive Executive Order aimed at strengthening and promoting the Nation's cybersecurity. Among the key measures is the requirement of encrypted DNS protocols for federal agencies.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/","og_locale":"en_US","og_type":"article","og_title":"The White House Executive Order: Requiring DNS as a Frontline Security Control","og_description":"Today, the White House issued a comprehensive Executive Order aimed at strengthening and promoting the Nation's cybersecurity. Among the key measures is the requirement of encrypted DNS protocols for federal agencies.","og_url":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/","og_site_name":"Infoblox Blog","article_published_time":"2025-01-16T14:35:00+00:00","article_modified_time":"2025-06-11T23:48:40+00:00","og_image":[{"width":800,"height":448,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg","type":"image\/jpeg"}],"author":"Dave Signori","twitter_card":"summary_large_image","twitter_title":"The White House Executive Order: Requiring DNS as a Frontline Security Control","twitter_description":"Today, the White House issued a comprehensive Executive Order aimed at strengthening and promoting the Nation's cybersecurity. Among the key measures is the requirement of encrypted DNS protocols for federal agencies.","twitter_image":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg","twitter_misc":{"Written by":"Dave Signori","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/"},"author":{"name":"Dave Signori","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/ce77af4c19aba94f344e3004644ae65e"},"headline":"The White House Executive Order: Requiring DNS as a Frontline Security Control","datePublished":"2025-01-16T14:35:00+00:00","dateModified":"2025-06-11T23:48:40+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/"},"wordCount":1138,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg","keywords":["Executive Order","Encrypted DNS","DNS Security","Infoblox ADP","Defense-in-Depth","DoT","DoH","cybersecurity compliance","Infoblox","CISA Guidance","White House"],"articleSection":["Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/","url":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/","name":"The White House Executive Order: Requiring DNS as a Frontline Security Control","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg","datePublished":"2025-01-16T14:35:00+00:00","dateModified":"2025-06-11T23:48:40+00:00","description":"Today, the White House issued a comprehensive Executive Order aimed at strengthening and promoting the Nation's cybersecurity. Among the key measures is the requirement of encrypted DNS protocols for federal agencies.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control-thumbnail.jpg","width":800,"height":448},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/security\/the-white-house-executive-order-requiring-dns-as-a-frontline-security-control\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.infoblox.com\/blog\/category\/security\/"},{"@type":"ListItem","position":3,"name":"The White House Executive Order: Requiring DNS as a Frontline Security Control"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/ce77af4c19aba94f344e3004644ae65e","name":"Dave Signori","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/live-infoblox-blog.pantheonsite.io\/wp-content\/uploads\/avatar_user_182_1571851798-96x96.jpg","url":"https:\/\/live-infoblox-blog.pantheonsite.io\/wp-content\/uploads\/avatar_user_182_1571851798-96x96.jpg","contentUrl":"https:\/\/live-infoblox-blog.pantheonsite.io\/wp-content\/uploads\/avatar_user_182_1571851798-96x96.jpg","caption":"Dave Signori"},"description":"VP of product management at Infoblox, the global leader in DNS, DHCP, and IP Address Management (DDI) supporting these services in 350 of the Fortune 500. Product management responsibilities for the Core DDI and network automation product lines. This includes DDI as well as discovery, hybrid cloud, traffic management, Microsoft management, analytics and NetMRI. Founding member of two successful start-ups including Emprisa Networks where as CTO held engineering, product management, pre-sales and professional services responsibilities. After Emprisa was acquired by BMC Software in 2007, stayed on at BMC as a director in product management for network automation, cloud life cycle management, and orchestration. Spends free time with family, travel, and playing in a classic rock \u2018dad\u2019 band.","url":"https:\/\/www.infoblox.com\/blog\/author\/dave-signori\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/10888","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/182"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=10888"}],"version-history":[{"count":12,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/10888\/revisions"}],"predecessor-version":[{"id":11878,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/10888\/revisions\/11878"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/10890"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=10888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=10888"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=10888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}