Free DISA STIG and SRG Library | Vaulted

V-74049

The Cisco IOS XE router must record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.

Finding ID
CISR-ND-000104
Rule ID
SV-88723r2_rule
Severity
Cat II
CCE
(None)
Group Title
SRG-APP-000375-NDM-000300
CCI
CCI-001889
Target Key
(None)
Documentable
No
Discussion

Without sufficient granularity of time stamps, it is not possible to adequately determine the chronological order of records. Time stamps generated by the application include date and time. Granularity of time measurements refers to the degree of synchronization between information system clocks and reference clocks.

Fix Text

Configure the Cisco IOS XE router to have a granularity of one second for audit log time stamps. The configuration should look like the example below: service timestamps debug datetime msec service timestamps log datetime year

Check Content

Verify that the time stamps for audit records have a granularity of one second. The configuration should look similar to the example below: service timestamps debug datetime msec service timestamps log datetime year If the time stamps have a granularity larger than one second, this is a finding.