Check: SRG-OS-000055-VMM-000250
Virtual Machine Manager SRG:
SRG-OS-000055-VMM-000250
(in versions v2 r2 through v1 r3)
Title
The VMM must use internal system clocks to generate time stamps for audit records. (Cat II impact)
Discussion
Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a VMM is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the VMM may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate.
Check Content
Verify the VMM uses internal system clocks to generate time stamps for audit records. If it does not, this is a finding.
Fix Text
Configure the VMM to use internal system clocks to generate time stamps for audit records.
Additional Identifiers
Rule ID: SV-207362r958432_rule
Vulnerability ID: V-207362
Group Title: SRG-OS-000055
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000159 |
Use internal system clocks to generate time stamps for audit records. |
Controls
Number | Title |
---|---|
AU-8 |
Time Stamps |