Technical controls implement DNS filtering, DNSSEC and monitoring to detect and block malicious domains
Filtering DNS resolution and locking public DNS records with registrar protections is a specific technical layer of the network protection A.8.20 requires.
The secure DNS technical facet points every device at a resolver that blocks known-malicious domains and locks the company's own DNS records, the core mechanism behind A.8.23's web filtering control.