18.8.49.1.1 Ensure 'Enable Windows NTP Client' is set to 'Enabled'

Information

This policy setting specifies whether the Windows NTP Client is enabled. Enabling the Windows NTP Client allows your computer to synchronize its computer clock with other NTP servers. You might want to disable this service if you decide to use a third-party time provider.

The recommended state for this setting is: 'Enabled'.

Rationale:
A reliable and accurate account of time is important for a number of services and security requirements, including but not limited to distributed applications, authentication services, multi-user databases and logging services. The use of an NTP client (with secure operation) establishes functional accuracy and is a focal point when reviewing security relevant events

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled:'


Computer Configuration\Policies\Administrative Templates\System\Windows Time Service\Time Providers\Enable Windows NTP Client


Note: This Group Policy path is provided by the Group Policy template 'W32Time.admx/adml' that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:
You can set the local computer clock to synchronize time with NTP servers.

See Also

https://workbench.cisecurity.org/files/1949

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CCE|CCE-37843-0, CSCv6|3.1, CSCv6|6.1

Plugin: Windows

Control ID: c3702241d80961ca7f061575a23194581839962361580a0c5da7e219dc70ce94