6. Zone Cuts
A "zone cut" is an instance of a delegation point. The parent side of the cut (the enclosing zone) contains NS records which indicate the delegation, and the child side contains the same NS records, as well as the A records for the name servers pointed to by the NS records.
6.1. Zone authority
The authority for a zone is indicated by the NS records at the zone cut. A server is authoritative for a zone if it is listed in the NS records for that zone, or if it is a server for a zone that encloses the zone (i.e. a parent zone).
A server must not be authoritative for a zone if it is not listed in the NS records for that zone, or in the NS records of an enclosing zone.
The SOA record for a zone must be at the top of the zone (the zone apex), and must not be present at a zone cut. That is, the SOA record for a zone is not present in the child zone at the zone cut.
6.2. DNSSEC issues
For DNSSEC [RFC2065], the zone cut has special significance. The SIG records that cover the NS records at the zone cut are in the parent zone, and the SIG records that cover the A records for the name servers are in the child zone. This means that the parent zone must be secure for the child zone to be considered secure.