3.10.42.1.1 (L1) Ensure 'Enable Windows NTP Client' is set to 'Enabled'

Information

This policy setting specifies whether the Windows NTP Client is enabled. Enabling the Windows NTP Client allows synchronization from a systems computer clock to NTP server(s).

The recommended state for this setting is: Enabled

Note: If a third-party time provider is used in the environment, an exception to this recommendation will be needed.

A reliable and accurate account of time is important for a number of services and security requirements, including but not limited to distributed applications, authentication services, multi-user databases and logging services. The use of an NTP client (with secure operation) establishes functional accuracy and is a focal point when reviewing security relevant events.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled

Administrative Templates\System\Windows Time Service\Time Providers\Enable Windows NTP Client

Impact:

System time will be synced to the configured NTP server(s).

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Windows

Control ID: c6abeae2527893d71e4d6e640b2b280bafccbb2bfeafca80535d394f92d4bab5