GEN000242 - The system must use at least two time sources for clock synchronization - service ntp server 1

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

A synchronized system clock is critical for the enforcement of time-based policies and the correlation of logs and audit records with other systems. For redundancy, two time sources are required so synchronization continues to function if one source fails.

If the system is completely isolated (no connections to networks or other systems), time synchronization is not required as no correlation of events or operation of time-dependent protocols between systems will be necessary. If the system is completely isolated, this requirement is not applicable.

NOTE: For the Network Time Protocol (NTP), the requirement is two servers, but it is recommended to configure at least four distinct time servers which allow NTP to effectively exclude a time source not consistent with the others. The system's local clock must be excluded from the count of time sources.

Solution

Add an additional server line to /etc/inet/ntp.conf for each additional NTP server.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R1_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-8(1), CAT|II, CCI|CCI-001891, CSCv6|6.1, Rule-ID|SV-227562r505926_rule, STIG-ID|GEN000242, STIG-Legacy|SV-26303, STIG-Legacy|V-22291, Vuln-ID|V-227562

Plugin: Unix

Control ID: f313b1f87629ac395bab22b474fcbc6e011f7d7215d4f037e42e2d172480b7c3