Check: SRG-APP-000116-AU-000270
Central Log Server SRG:
SRG-APP-000116-AU-000270
(in versions v2 r2 through v1 r0.1)
Title
The Central Log Server must be configured to use internal system clocks to generate time stamps for log records. (Cat III impact)
Discussion
Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate. Applications can use the capability of an operating system or purpose-built module for this purpose.
Check Content
Examine the configuration. Verify the Central Log Server uses internal system clocks to generate time stamps for log records. If the Central Log Server is not configured to use internal system clocks to generate time stamps for log records, this is a finding.
Fix Text
Configure the Central Log Server to use internal system clocks to generate time stamps for log records.
Additional Identifiers
Rule ID: SV-206457r395817_rule
Vulnerability ID: V-206457
Group Title: SRG-APP-000116
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000159 |
The information system uses internal system clocks to generate time stamps for audit records. |
Controls
Number | Title |
---|---|
AU-8 |
Time Stamps |