UCF STIG Viewer Logo

The IDPS must synchronize internal system clocks on an organizationally defined frequency with an organizationally defined authoritative time source.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34572 SRG-NET-000097-IDPS-00071 SV-45427r1_rule Low
Description
The various components within the network infrastructure providing the log records must have their clocks synchronized using a common time reference, so the events can be correlated in exact order of time. Without synchronized time, accurately correlating information between devices becomes difficult, if not impossible. If sensor logs cannot be correlated with the routers, switches, and firewalls, it may not be possible to trace all the damage caused by a network breach. The IDPS must be configured to use a minimum of two Network Time Protocol (NTP) servers to synchronize time. NTP provides an efficient and scalable method for network elements to synchronize to an accurate time source.
STIG Date
Intrusion Detection and Prevention Systems (IDPS) Security Requirements Guide 2012-11-19

Details

Check Text ( C-42776r1_chk )
Verify two NTP servers have been defined by checking the IDPS configuration. View the configuration and verify time synchronization occurs.

If the IDPS does not synchronize internal system clocks on an organizationally defined frequency with an NTP server, this is a finding.
Fix Text (F-38824r1_fix)
Specify two NTP server IP addresses on the device in the IDPS configuration.