Check: APPL-14-000014
Apple macOS 14 (Sonoma) STIG:
APPL-14-000014
(in versions v1 r2 through v1 r1)
Title
The macOS system must enforce time synchronization. (Cat II impact)
Discussion
Time synchronization must be enforced on all networked systems. This rule ensures the uniformity of time stamps for information systems with multiple system clocks and systems connected over a network. Satisfies: SRG-OS-000355-GPOS-00143,SRG-OS-000356-GPOS-00144
Check Content
Verify the macOS system is configured to enforce time synchronization with the following command: /usr/bin/osascript -l JavaScript << EOS $.NSUserDefaults.alloc.initWithSuiteName('com.apple.timed')\ .objectForKey('TMAutomaticTimeOnlyEnabled').js EOS If the result is not "true", this is a finding.
Fix Text
Configure the macOS system to enforce time synchronization by installing the "com.apple.timed" configuration profile.
Additional Identifiers
Rule ID: SV-259425r940897_rule
Vulnerability ID: V-259425
Group Title: SRG-OS-000355-GPOS-00143
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001891 |
The information system compares internal information system clocks on an organization-defined frequency with an organization-defined authoritative time source. |
CCI-002046 |
The information system synchronizes the internal system clocks to the authoritative time source when the time difference is greater than the organization-defined time period. |
Controls
Number | Title |
---|---|
AU-8 (1) |
Synchronization With Authoritative Time Source |