Check: SRG-OS-000055-GPOS-00026
General Purpose Operating System SRG:
SRG-OS-000055-GPOS-00026
(in versions v2 r7 through v1 r4)
Title
The operating system must use internal system clocks to generate time stamps for audit records. (Cat II impact)
Discussion
Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate.
Check Content
Verify the operating system uses internal system clocks to generate time stamps for audit records. If it does not, this is a finding.
Fix Text
Configure the operating system to use internal system clocks to generate time stamps for audit records.
Additional Identifiers
Rule ID: SV-203615r557103_rule
Vulnerability ID: V-203615
Group Title: SRG-OS-000055
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000159 |
The information system uses internal system clocks to generate time stamps for audit records. |
Controls
Number | Title |
---|---|
AU-8 |
Time Stamps |