STIGQter STIGQter: STIG Summary: Central Log Server Security Requirements Guide Version: 1 Release: 4 Benchmark Date: 24 Jul 2020:

Time stamps recorded on the log records in the Central Log Server must be configured to synchronize to within one second of the host server or, if NTP is configured directly in the log server, the NTP time source must be the same as the host and devices within its scope of coverage.

DISA Rule

SV-95823r1_rule

Vulnerability Number

V-81109

Group Title

SRG-APP-000086-AU-000030

Rule Version

SRG-APP-000086-AU-000030

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the Central Log Server such that time stamps on the log records are synchronized to within one second of the host server.

If applicable, configure the Central Log Server NTP client to use the same NTP time source as the host and devices within its scope of coverage.

Check Contents

Examine the time stamp that indicates when the Central Log Server received the log records.

Verify the time is synchronized to within one second of the host server.

If an NTP client is configured within the Central Log Server application, verify it is configured to use the same NTP time source as the host and devices within its scope of coverage.

If time stamps recorded on the log records in the Central Log Server are not configured to synchronize to within one second of the host server or the log server application is not configured to use the same NTP time source as the host and devices within its scope of coverage, this is a finding.

Vulnerability Number

V-81109

Documentable

False

Rule Version

SRG-APP-000086-AU-000030

Severity Override Guidance

Examine the time stamp that indicates when the Central Log Server received the log records.

Verify the time is synchronized to within one second of the host server.

If an NTP client is configured within the Central Log Server application, verify it is configured to use the same NTP time source as the host and devices within its scope of coverage.

If time stamps recorded on the log records in the Central Log Server are not configured to synchronize to within one second of the host server or the log server application is not configured to use the same NTP time source as the host and devices within its scope of coverage, this is a finding.

Check Content Reference

M

Target Key

3395

Comments