Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-8324 | DS00.0151_AD | SV-8819r3_rule | ECTM-1 ECTM-2 | Low |
Description |
---|
When a time synchronization tool executes, it may switch between time sources according to network or server contention. If switches between time sources are not logged, it may be difficult or impossible to detect malicious activity or availability problems. |
STIG | Date |
---|---|
Active Directory Service 2008 Security Technical Implementation Guide (STIG) | 2011-05-23 |
Check Text ( C-13256r2_chk ) |
---|
If Windows Time Service is used as the time synchronization tool, use the following procedures to determine if logging is configured to capture time source switches. Windows Time Service 1. Use Registry Editor to navigate to HKLM\System\CurrentControlSet\Services\W32Time\Config. 2. If the value for “EventLogFlags” is not “2”, then this is a finding. If the NTP daemon or another tool is used as the time synchronization tool, use the following proceudres. 1. Request the assistance of the SA or application SA to determine if the tool is logging time source changes. 2. Review the available configuration options and logs. 3. If the tool has time source logging capability and it is not enabled, then this is a finding. |
Fix Text (F-14380r2_fix) |
---|
Update the time synchronization tool configuration so that time source switching is logged. |