Overview

Security Requirements for 03.03.07 Authoritative Time Source

Internal system clocks are used to generate time stamps, which include date and time. Time is expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC. The granularity of time measurements refers to the degree of synchronization between system clocks and reference clocks, for example, clocks synchronizing within hundreds of milliseconds or within tens of milliseconds. Organizations may define different time granularities for different system components. Time service can also be critical to other security capabilities such as access control and identification and authentication, depending on the nature of the mechanisms used to support those capabilities. This requirement provides uniformity of time stamps for systems with multiple system clocks and systems connected over a network. See [IETF 5905].

Evidence

  1. 03.03.07.a

    Internal system clocks are used to generate time stamps for audit records

  1. 03.03.07.b

    An authoritative source with which to compare and synchronize internal system clocks is specified

  1. 03.03.07.c

    Internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source