UCF STIG Viewer Logo

The Mainframe Products must use internal system clocks to generate time stamps for audit records.


Overview

Finding ID Version Rule ID IA Controls Severity
V-68289 SRG-APP-000116-MFP-000171 SV-82779r1_rule Medium
Description
Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate. Applications can use the capability of an operating system or purpose-built module for this purpose.
STIG Date
Mainframe Product Security Requirements Guide 2019-12-12

Details

Check Text ( C-68849r1_chk )
Examine installation and configuration settings.

If the Mainframe Product does not use the z/OS system clock for audit time stamps, this is a finding.
Fix Text (F-74403r1_fix)
Configure the Mainframe Product to use the z/OS system clock for audit time stamps.