1Overview
AU.L2-3.3.7 makes the timestamps in audit records trustworthy. It requires that systems compare and synchronize their internal clocks with an authoritative time source, so that the time stamps on audit records are accurate and consistent across systems. It is a one-point requirement and may be deferred on a plan of action, though it quietly underpins every investigation.
Time is the axis every investigation runs along. To reconstruct what happened, an analyst orders events by their time stamps, and if the clocks on different systems disagree, that ordering breaks: an event that came first appears to come second, and the sequence that would reveal an intrusion is scrambled. This control requires that internal clocks be synchronized to an authoritative source, so that time stamps are accurate and comparable across the environment. It is a small technical measure with outsized importance, because correlation and investigation both depend on a shared, correct clock.
Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.
The requirement ties three things together: internal clocks generate the time stamps, an authoritative source defines correct time, and synchronization keeps the clocks aligned to it. The authoritative source is typically a reliable time service the organization designates, and synchronization is usually automatic through the time protocol built into the systems. The control is met when the systems that generate audit records keep their clocks synchronized to that source, so time stamps can be trusted and compared.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.3.7 into three objectives: use internal clocks for time stamps, specify the authoritative source, and synchronize to it.
Internal system clocks are used to generate time stamps for audit records. Records are time-stamped from the system clock.
An authoritative source with which to compare and synchronize internal system clocks is specified. The organization has designated a correct-time source.
Internal system clocks used to generate time stamps are compared to and synchronized with the specified authoritative source. The clocks are kept aligned to the source.
The three objectives move from time-stamping to specifying a source to synchronizing with it. The common gap is at objectives [b] and [c], where systems are never pointed at a common authoritative source, so their clocks drift apart and cross-system time stamps cannot be trusted. The assessor looks for synchronization to a designated source across the systems that generate records.
3Failure Patterns
The failures are about unsynchronized clocks and the scrambled event ordering they cause.
Clocks that drift apart
Without synchronization, system clocks drift, and after a while different systems disagree on the time by seconds or minutes. During an investigation that spans systems, that disagreement scrambles the true order of events, which is the harm the control prevents.
No specified source
Where no authoritative source is designated, there is nothing to correct drift against, so objective [b] fails and synchronization has no anchor. A specified source is the reference the whole control depends on.
Some systems left unsynchronized
If most systems synchronize but a few do not, the records from those few carry untrustworthy time stamps and break correlation. Synchronization has to reach the systems that generate audit records, not just the majority.
Inconsistent time zones or formats
Records stamped in inconsistent local time zones without a common reference can confuse ordering even when clocks are technically synchronized. A consistent reference, often coordinated universal time, keeps time stamps comparable.
4Ownership
This is an IT-owned technical control, usually satisfied by the time synchronization built into the environment.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Specifies the authoritative time source and configures systems to synchronize to it. Owns the technical evidence. |
| Security or compliance lead | Confirms synchronization reaches the systems that generate audit records and that time stamps are consistent. |
| Program lead | Includes time synchronization in periodic checks and retains the configuration evidence. |
5Tooling
The control is delivered by the time protocol built into the systems, pointed at a designated source.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | System clock time-stamping | Audit records stamped from the system clock. |
| [b] | Designated time source, such as an internal NTP server or reliable service | The authoritative source clocks are synchronized to. |
| [c] | NTP or the domain time hierarchy, consistent time reference | Automatic synchronization of clocks to the source across the systems that generate records. |
The caveat is that synchronization has to reach every system that generates audit records and use a consistent reference. A domain time hierarchy anchored to a reliable source covers most systems automatically, but standalone or cloud systems have to be pointed at the source too. The assessor examines the time source and synchronization across the record-generating systems, so coverage and consistency both have to hold.
6Evidence
The satisfied version of 3.3.7 shows a specified source and synchronized clocks across the environment.
| Evidence | What it demonstrates |
|---|---|
| Specified time source | Objective [b]. The designated authoritative source. |
| Time synchronization configuration | Objectives [a], [c]. Systems generating time stamps and synchronizing to the source. |
| Synchronization status across systems | Objective [c]. Evidence that record-generating systems are actually synchronized. |
The evidence should show a designated authoritative source and synchronized clocks on the systems that generate audit records. Configuration pointing systems at the source, plus confirmation they are in sync, is the clearest demonstration of the control.
Investigations run on a shared clock
Unsynchronized clocks scramble the order of events across systems, and the damage surfaces exactly when an investigation needs to reconstruct a sequence. Pointing every record-generating system at a common authoritative time source is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.3.7. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.3.7[a] through 3.3.7[c]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov