Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-32392 | SRG-APP-000117-DB-000058 | SV-42729r1_rule | Medium |
Description |
---|
Determining the correct time a particular application event occurred on a system is critical when conducting forensic analysis and investigating system events. Synchronization of system clocks is needed in order to correctly correlate the timing of events that occur across multiple systems. To meet that requirement the organization will define an authoritative time source and frequency to which each system will synchronize its internal clock. An example is utilizing the NTP protocol to synchronize with centralized NTP servers. Timestamps generated by the information system shall include both date and time. The time may be expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC. Applications not purposed to provide NTP services should not try to compete with or replace NTP functionality and should synchronize with internal information system clocks that are in turn synchronized with an organization defined authoritative time source. |
STIG | Date |
---|---|
Database Security Requirements Guide | 2012-07-02 |
Check Text ( C-40834r1_chk ) |
---|
Review DBMS settings to determine if it is synchronizing with the internal information system clock. If audit records are being time stamped with times that are not from a synchronized source, this is a finding. |
Fix Text (F-36307r1_fix) |
---|
Modify DBMS settings to synchronize internal DBMS clock with information system clock. Timestamps must use a time source that has been synchronized with the internal information system clock. |