1.7.2 Configure a Time Zone

Information

Timezones are a source of contention in larger corporations. On one hand, if infrastructure is configured with time consistent with the local timezone, then it is simpler to co-relate end-user symptoms and logs on end-user equipment with logs from network equipment. On the other hand, in organizations that span multiple time zones, configuring local time can make it easy to mis-match log entries from gear in different time zones.

In some organizations, the solution is to post both local and UTC time in all log entries. In other organizations, all gear is configured for one timezone (either UTC or 'head office time').

The important thing is to have a standard for time zone, and to configure it consistently across all hosts and infrastructure equipment.

Rationale:

Impact:

Not having a consistent time zone policy across all hosts and infrastructure means that when dealing with a security incident or technical issue, it becomes very easy to mis-match logs as affected hosts span multiple time zones.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

To set the timezone, define the timezone name, the offset in hours, then the offset in seconds. The example below shows EST (Offset of -5 hours, zero seconds).

switch(config)# clock timezone EST -5 0

Default Value:

By default UTC is set

See Also

https://workbench.cisecurity.org/benchmarks/6524

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Cisco

Control ID: 274e51c715b9c9c9d5c7bd136bb1740467e07eb044fdbf800d77f755e73b8acc