Check: APPL-14-000180
Apple macOS 14 (Sonoma) STIG:
APPL-14-000180
(in versions v1 r2 through v1 r1)
Title
The macOS system must enable time synchronization daemon. (Cat II impact)
Discussion
The macOS time synchronization daemon (timed) must be enabled for proper time synchronization to an authorized time server. Note: The time synchronization daemon is enabled by default on macOS. Satisfies: SRG-OS-000355-GPOS-00143,SRG-OS-000356-GPOS-00144
Check Content
Verify the macOS system is configured to enable time synchronization daemon with the following command: /bin/launchctl list | /usr/bin/grep -c com.apple.timed If the result is not "1", this is a finding.
Fix Text
Configure the macOS system to enable time synchronization daemon with the following command: /bin/launchctl load -w /System/Library/LaunchDaemons/com.apple.timed.plist
Additional Identifiers
Rule ID: SV-259451r940975_rule
Vulnerability ID: V-259451
Group Title: SRG-OS-000355-GPOS-00143
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001891 |
The information system compares internal information system clocks on an organization-defined frequency with an organization-defined authoritative time source. |
CCI-002046 |
The information system synchronizes the internal system clocks to the authoritative time source when the time difference is greater than the organization-defined time period. |
Controls
Number | Title |
---|---|
AU-8 (1) |
Synchronization With Authoritative Time Source |