Free DISA STIG and SRG Library | Vaulted

V-81123

The Central Log Server must be configured to use internal system clocks to generate time stamps for log records.

Finding ID
SRG-APP-000116-AU-000270
Rule ID
SV-95837r1_rule
Severity
Cat III
CCE
(None)
Group Title
SRG-APP-000116-AU-000270
CCI
CCI-000159
Target Key
(None)
Documentable
No
Discussion

Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate. Applications can use the capability of an operating system or purpose-built module for this purpose.

Fix Text

Configure the Central Log Server to use internal system clocks to generate time stamps for log records.

Check Content

Examine the configuration. Verify the Central Log Server uses internal system clocks to generate time stamps for log records. If the Central Log Server is not configured to use internal system clocks to generate time stamps for log records, this is a finding.