STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2012/2012 R2 Domain Controller Security Technical Implementation Guide Version: 3 Release: 2 Benchmark Date: 04 May 2021:

The time synchronization tool must be configured to enable logging of time source switching.

DISA Rule

SV-226077r569184_rule

Vulnerability Number

V-226077

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

WN12-AD-000008-DC

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the time synchronization tool to log time source switching. If the Windows Time Service is used, configure the following registry value.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\W32Time\Config\

Value Name: EventLogFlags

Type: REG_DWORD
Value: 2 or 3

Check Contents

Verify logging is configured to capture time source switches.

If the Windows Time Service is used, verify the following registry value. If it is not configured as specified, this is a finding.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\W32Time\Config\

Value Name: EventLogFlags

Type: REG_DWORD
Value: 2 or 3

If another time synchronization tool is used, review the available configuration options and logs. If the tool has time source logging capability and it is not enabled, this is a finding.

Vulnerability Number

V-226077

Documentable

False

Rule Version

WN12-AD-000008-DC

Severity Override Guidance

Verify logging is configured to capture time source switches.

If the Windows Time Service is used, verify the following registry value. If it is not configured as specified, this is a finding.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \System\CurrentControlSet\Services\W32Time\Config\

Value Name: EventLogFlags

Type: REG_DWORD
Value: 2 or 3

If another time synchronization tool is used, review the available configuration options and logs. If the tool has time source logging capability and it is not enabled, this is a finding.

Check Content Reference

M

Target Key

4217

Comments