Check: SRG-APP-000116-AAA-000320
Authentication, Authorization, and Accounting Services (AAA) SRG:
SRG-APP-000116-AAA-000320
(in versions v1 r2 through v1 r1)
Title
AAA Services must be configured to use internal system clocks to generate time stamps for audit records. (Cat II impact)
Discussion
Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate. Applications can use the capability of an operating system or purpose-built module for this purpose. Synchronizing the internal clock using NTP provides uniformity for all system clocks over a network. NTP provides an efficient and scalable method for network devices to synchronize to an accurate time source.
Check Content
Verify AAA Services are configured to use internal system clocks to generate time stamps for audit records. If AAA Services are not configured to use internal system clocks to generate time stamps for audit records, this is a finding.
Fix Text
Configure AAA Services to use internal system clocks to generate time stamps for audit records.
Additional Identifiers
Rule ID: SV-95587r1_rule
Vulnerability ID: V-80877
Group Title: SRG-APP-000116-AAA-000320
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000159 |
The information system uses internal system clocks to generate time stamps for audit records. |
Controls
Number | Title |
---|---|
AU-8 |
Time Stamps |