The Central Log Server must be configured to use internal system clocks to generate time stamps for log records.

From Central Log Server Security Requirements Guide

Part of SRG-APP-000116-AU-000270

Associated with: CCI-000159

SRG-APP-000116-AU-000270_rule The Central Log Server must be configured to use internal system clocks to generate time stamps for log records.

Vulnerability discussion

Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate. Applications can use the capability of an operating system or purpose-built module for this purpose.

Check content

Examine the configuration. Verify the Central Log Server uses internal system clocks to generate time stamps for log records. If the Central Log Server is not configured to use internal system clocks to generate time stamps for log records, this is a finding.

Fix text

Configure the Central Log Server to use internal system clocks to generate time stamps for log records.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer