CCI|CCI-004923

Title

Compare the internal system clocks on an organization-defined frequency with organization-defined authoritative time source.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
APPL-14-000014 - The macOS system must enforce time synchronization.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-000170 - The macOS system must be configured to use an authorized time server.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-000180 - The macOS system must enable time synchronization daemon.UnixDISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-15-000014 - The macOS system must enforce time synchronization.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-000170 - The macOS system must be configured to use an authorized time server.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-000180 - The macOS system must enable the time synchronization daemon.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
ARST-ND-000600 - The Arista network device must be configured to synchronize internal system clocks using redundant authenticated time sources.AristaDISA STIG Arista MLS EOS 4.2x NDM v2r1
CASA-ND-000940 - The Cisco ASA must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources - ntp serverCiscoDISA STIG Cisco ASA NDM v2r1
CASA-ND-000940 - The Cisco ASA must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources - ntp server preferCiscoDISA STIG Cisco ASA NDM v2r1
CISC-ND-001030 - The Cisco router must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.CiscoDISA STIG Cisco IOS Router NDM v3r1
CISC-ND-001030 - The Cisco router must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.CiscoDISA STIG Cisco IOS XE Router NDM v3r1
CISC-ND-001030 - The Cisco router must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.CiscoDISA STIG Cisco IOS-XR Router NDM v3r1
CISC-ND-001030 - The Cisco switch must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.CiscoDISA STIG Cisco IOS XE Switch NDM v3r1
CISC-ND-001030 - The Cisco switch must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.CiscoDISA STIG Cisco IOS Switch NDM v3r1
CISC-ND-001030 - The Cisco switch must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.CiscoDISA STIG Cisco NX-OS Switch NDM v3r1
ESXI-80-000124 The ESXi host must synchronize internal information system clocks to an authoritative time source.VMwareDISA VMware vSphere 8.0 ESXi STIG v2r1
JUEX-NM-000430 - The Juniper EX switch must be configured to synchronize internal information system clocks using redundant authoritative time sources.JuniperDISA Juniper EX Series Network Device Management v2r1
JUNI-ND-001020 - The Juniper router must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.JuniperDISA STIG Juniper Router NDM v3r1
OL08-00-030740 - OL 8 must compare internal information system clocks at least every 24 hours with a server synchronized to an authoritative time source, such as the United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).UnixDISA Oracle Linux 8 STIG v2r1
PANW-NM-000098 - The Palo Alto Networks security platform must compare internal information system clocks at least every 24 hours with an authoritative time server.Palo_AltoDISA STIG Palo Alto NDM v3r1
PANW-NM-000099 - The Palo Alto Networks security platform must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second.Palo_AltoDISA STIG Palo Alto NDM v3r1
RHEL-08-030740 - RHEL 8 must securely compare internal information system clocks at least every 24 hours with a server synchronized to an authoritative time source, such as the United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).UnixDISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-09-252010 - RHEL 9 must have the chrony package installed.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-252015 - RHEL 9 chronyd service must be enabled.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-252020 - RHEL 9 must securely compare internal information system clocks at least every 24 hours.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
SLES-15-010400 - The SUSE operating system clock must, for networked systems, be synchronized to an authoritative DOD time source at least every 24 hours.UnixDISA SLES 15 STIG v2r1
UBTU-20-010435 - The Ubuntu operating system must, for networked systems, compare internal information system clocks at least every 24 hours with a server which is synchronized to one of the redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).UnixDISA STIG Ubuntu 20.04 LTS v2r1
UBTU-22-252010 - Ubuntu 22.04 LTS must, for networked systems, compare internal information system clocks at least every 24 hours with a server synchronized to one of the redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).UnixDISA STIG Canonical Ubuntu 22.04 LTS v2r2
VCSA-80-000158 The vCenter Server must compare internal information system clocks at least every 24 hours with an authoritative time server.VMwareDISA VMware vSphere 8.0 vCenter STIG v2r1
WN11-00-000260 - The Windows 11 time service must synchronize with an appropriate DOD time source.WindowsDISA Windows 11 STIG v2r2
WN19-00-000440 - The Windows Server 2019 time service must synchronize with an appropriate DOD time source.WindowsDISA Windows Server 2019 STIG v3r2
WN22-00-000440 - The Windows Server 2022 time service must synchronize with an appropriate DOD time source.WindowsDISA Windows Server 2022 STIG v2r2