CMMCpedia Download

Requirements / Audit and Accountability (AU)

AU.L2-3.3.7

Authoritative Time Source

Official Source Material

Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.

Determine if:

  1. [a] internal system clocks are used to generate time stamps for audit records;
  2. [b] an authoritative source with which to compare and synchronize internal system clocks is specified; and
  3. [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Specify one authoritative time source and point everything at it.

Objective [b] says an authoritative source, singular. Systems split across unrelated time sources invite the question of whether their logs can be compared. Name the source in your system security plan, the document that describes how your system meets each requirement. Where a device cannot use it, record the deviation and show the clocks still agree.

Most of this already works. The job is naming it and proving it.

Domain joined Windows machines sync through the domain hierarchy, and cloud platforms sync their own infrastructure. Network gear takes an NTP setting, the standard network time protocol. Objective [c] wants the comparing and synchronizing shown, so capture the time service status from a server and the NTP configuration page from your firewall.

You cannot set the clock on a cloud service, so document it instead.

A provider's platform clocks are outside your control. Record in the system security plan that the provider synchronizes its own infrastructure. Review logs in UTC, coordinated universal time, so records from different systems line up without time zone arithmetic during an investigation.

What falls short

  • Workstations synced to one public time service, the firewall to another, and no evidence the two agree. Objective [b] names a source and this setup names several without justification.

Edge cases

  • An appliance that forces the vendor's own time service cannot follow your specified source. Document the exception and show its timestamps align with your other logs, because alignment is the outcome the requirement protects.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.