Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-206457 | SRG-APP-000116-AU-000270 | SV-206457r395817_rule | Low |
Description |
---|
Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate. Applications can use the capability of an operating system or purpose-built module for this purpose. |
STIG | Date |
---|---|
Central Log Server Security Requirements Guide | 2021-06-24 |
Check Text ( C-6717r285615_chk ) |
---|
Examine the configuration. Verify the Central Log Server uses internal system clocks to generate time stamps for log records. If the Central Log Server is not configured to use internal system clocks to generate time stamps for log records, this is a finding. |
Fix Text (F-6717r285616_fix) |
---|
Configure the Central Log Server to use internal system clocks to generate time stamps for log records. |