More Info:

AWS Route 53 registered domains should be locked to prevent any unauthorized transfers to another domain name registrar.

Risk Level

Low

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

Sure, here are the steps to remediate the misconfiguration of unlocked Route 53 domains in AWS:

  1. Open the AWS Management Console and go to the Route 53 service.

  2. In the left navigation pane, click on the Registered domains option.

  3. Select the domain that you want to lock.

  4. In the domain details page, click on the “Add/Edit Tags” button.

  5. In the “Add/Edit Tags” dialog box, click on the “Add tag” button.

  6. In the “Key” field, enter “LockDomain” and in the “Value” field, enter “True”.

  7. Click on the “Save changes” button to save the tag.

  8. After adding the tag, click on the “Lock domain” button to lock the domain.

  9. In the “Lock domain” dialog box, review the information and click on the “Lock domain” button to confirm.

  10. Once the domain is locked, you will see the “Domain lock enabled” message on the domain details page.

Congratulations! You have successfully remediated the misconfiguration of unlocked Route 53 domains in AWS.

Additional Reading: