WN12-AD-000008-DC - The time synchronization tool must be configured to enable logging of time source switching.

Information

When a time synchronization tool executes, it may switch between time sources according to network or server contention. If switches between time sources are not logged, it may be difficult or impossible to detect malicious activity or availability problems.

Solution

Configure the time synchronization tool to log time source switching. If the Windows Time Service is used, configure the following registry value.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\W32Time\Config\

Value Name: EventLogFlags

Type: REG_DWORD
Value: 2 or 3

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_DC_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-226077r794796_rule, STIG-ID|WN12-AD-000008-DC, STIG-Legacy|SV-51182, STIG-Legacy|V-8324, Vuln-ID|V-226077

Plugin: Windows

Control ID: bbac4f0ef9f37a3d1e46b3aec0e2e31d06ecd65622b91ed097187d5df502fd8c