Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-35204 | SRG-APP-000117-AS-000077 | SV-46491r1_rule | Low |
Description |
---|
Determining the correct time a particular application event occurred on a system is critical when conducting forensic analysis and investigating system events. Synchronization of system clocks is needed in order to correctly correlate the timing of events that occur across multiple systems. To meet that requirement the organization will define an authoritative time source and frequency to which each system will synchronize its internal clock. Application servers must defer accurate timekeeping services to the operating system upon which the AS is installed. |
STIG | Date |
---|---|
Application Server Security Requirements Guide | 2013-01-08 |
Check Text ( C-43576r1_chk ) |
---|
Review AS documentation and confirm that the AS defers to the operating system for accurate timekeeping. If the AS provides its own timekeeping service, this is a finding. |
Fix Text (F-39750r2_fix) |
---|
Configure the AS to utilize the timekeeping services of the host OS. |