Check: SRG-APP-000374-DB-000322
Database SRG:
SRG-APP-000374-DB-000322
(in versions v4 r2 through v2 r9)
Title
The DBMS must record time stamps, in audit records and application data, that can be mapped to Coordinated Universal Time (UTC, formerly GMT). (Cat II impact)
Discussion
If time stamps are not consistently applied and there is no common time reference, it is difficult to perform forensic analysis. Time stamps generated by the DBMS must include date and time. Time is commonly expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC. Some DBMS products offer a data type called TIMESTAMP that is not a representation of date and time. Rather, it is a database state counter and does not correspond to calendar and clock time. This requirement does not refer to that meaning of TIMESTAMP.
Check Content
Verify that the DBMS generates time stamps, in audit records and application data, that maps to UTC. If it does not, this is a finding.
Fix Text
Ensure the DBMS generates time stamps, in audit records and application data, that maps to UTC.
Additional Identifiers
Rule ID: SV-206594r961443_rule
Vulnerability ID: V-206594
Group Title: SRG-APP-000374
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001890 |
Record time stamps for audit records that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp. |
Controls
Number | Title |
---|---|
AU-8 |
Time Stamps |