SRS-063: Accurate Time Synchronization
Identifier​
SRS-063
Software System​
- Operating System Layer
- Audit Service
- All services that generate timestamps
Category​
- Security
- Infrastructure
- Data Integrity
Description​
The system's internal clock shall be periodically synchronized with a trusted and secure Network Time Protocol (NTP) source to ensure the accuracy and reliability of all timestamps used in audit records and throughout the system.
- NTP synchronization: The device's operating system shall be configured to synchronize its clock with one or more designated, secure, and highly-available NTP servers.
- Synchronization frequency: Clock synchronization shall occur at a pre-configured, regular interval sufficient to prevent significant clock drift and maintain time accuracy within a defined tolerance.
- Trusted time source: The NTP source(s) must be verified as trusted and secure to prevent malicious time-shifting attacks.
- Failure handling: The system shall log any failures to synchronize with the NTP source and implement a fail-safe mechanism, such as falling back to a secondary NTP server.
Derived from PRS​
- PRS-0MC: Comprehensive secure audit trails for user interactions