Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should teams do when they need to…
Governance, Ownership & Risk

What should teams do when they need to secure both new and existing domains?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Standardise the baseline before adding more domains. Use templates for DNS records, enforce registrar access controls, document ownership, and apply the same review process to legacy domains and new launches so older assets do not become the weakest part of the portfolio.

How to Secure New and Existing Domains on the Same Baseline

Teams usually get into trouble when new domains are treated as a separate programme and legacy domains are left to “keep working.” A stronger approach is to define a common control baseline, then apply it to both launch activities and older assets. That keeps ownership, access, review cadence, and record quality aligned across the portfolio instead of drifting by age.

For domain portfolios, the baseline should be practical rather than abstract. The same minimum standard should cover how records are created, who can change them, how changes are approved, and how ownership is recorded. NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it ties this work to access control, authentication, auditability, and configuration discipline.

That also means treating “new” and “existing” as a single operating model. New domains should inherit the same templates, registration checks, and review steps as legacy domains, while older domains should be brought back into the same process rather than managed by exception. The goal is not just consistency for its own sake, but reducing the chance that an old, forgotten domain becomes the easiest point of compromise.

Where Domain Security Usually Breaks Down

The common failure is uneven governance. Teams often secure high-visibility launches carefully, then allow older domains to keep stale records, unclear ownership, or broad registrar access. CSA Cloud Controls Matrix is relevant because it reflects the same governance pattern across IAM, audit, and operational control domains, which is exactly what domain portfolios need.

Another weak point is access sprawl. If multiple people can change registrar settings without a clear approval path, the control boundary becomes too loose to trust. NIST Cybersecurity Framework 2.0 supports the broader expectation that asset ownership, protective controls, and governance processes should be repeatable, not ad hoc.

Legacy domains also create blind spots because the team assumes they are stable. In practice, they often have the longest-lived ownership gaps, the weakest documentation, and the most inconsistent review history. That is where compromise or misdirection becomes more likely, especially if the organisation has never forced a full inventory and control review across the whole portfolio.

What a Sustainable Domain Control Model Looks Like

A sustainable model starts with standard templates for DNS and domain setup, then applies the same approval, review, and rollback discipline to every domain. Documented ownership should identify who approves changes, who monitors the asset, and who can intervene if records or registrar settings change unexpectedly. If a team cannot name those roles quickly, the control design is not mature enough.

Registrar access should be narrowly controlled, with privileged changes reserved for the smallest practical group and logged for review. NIST SP 800-207 Zero Trust Architecture is not about domains specifically, but its “verify, do not assume” mindset fits this problem well, because domain administration should never rely on informal trust or inherited access.

Teams should also use the same review rhythm for every domain, regardless of age. New launches need launch-day checks, but older domains need the same periodic review for ownership, resolver records, registrar permissions, and any dependency that could redirect traffic or expose the brand. That is how the baseline becomes real rather than a document that only applies to fresh projects.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementDomain ownership and registrar access need controlled assignment and review.
AC-6 — Least PrivilegeRegistrar changes should be limited to the smallest set of trusted admins.
AU-2 — Event LoggingChange visibility matters when DNS or registrar settings can redirect traffic.
Recommendation — Restrict registrar access to approved owners and review it on a fixed cadence. Minimise registrar privileges and separate day-to-day admins from approvers. Log domain and registrar changes so reviews can detect unauthorised edits.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsA complete domain inventory is the basis for applying the same control baseline.
A.5.15 — Access controlRegistrar access and DNS update rights require explicit control and review.
Recommendation — Maintain an authoritative inventory of domains, owners, and renewal status. Apply formal access control to registrar and DNS administration paths.

Practitioner Guidance

What to prioritise: Start with a single domain inventory that lists owner, registrar, renewal status, and who can make changes. If you cannot prove who controls an existing domain, treat it as an active security problem rather than a housekeeping issue.

What to verify: Confirm that the same review checklist is used for both launch and legacy domains, and that it includes access control, DNS change approval, and recovery contacts. If older domains are exempt from the process, the baseline is not actually standardised.

Common mistake: Teams often secure the acquisition or launch workflow but never retroactively normalise old domains. That creates a portfolio where risk accumulates in the least visible assets.

Practitioner takeaway: The right standard is portfolio-wide consistency, not perfect treatment of only the newest assets. If the control cannot be applied to an old domain with the same rigor as a new one, it is not yet the baseline you should trust.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org