← Controls / AU

AU-08 Time Stamps

Audit and Accountability

Low Moderate High

Description

a. Use internal system clocks to generate time stamps for audit records; and b. Record time stamps for audit records that meet [Assignment: organization-defined granularity of time measurement] and that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.

Supplemental Guidance

Time stamps generated by the system include date and time. Time is commonly expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC. Granularity of time measurements refers to the degree of synchronization between system clocks and reference clocks (e.g., clocks synchronizing within hundreds of milliseconds or tens of milliseconds). Organizations may define different time granularities for different system components. Time service can be critical to other security capabilities such as access control and identification and authentication, depending on the nature of the mechanisms used to support those capabilities.

Enhancements (0)

NIST has withdrawn every enhancement this control had.

  • AU-08(01) Synchronization with Authoritative Time Source, now in SC-45(01)
  • AU-08(02) Secondary Authoritative Time Source, now in SC-45(02)

Patterns that use this control (6)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

7.5A.8.15A.8.17

ISO 27002:2022

8.158.17

CIS Controls v8

CIS 8CIS 8.4

PCI DSS v4.0.1

10.6

CSA CCM v4

LOG-06

CSA AICM v1

LOG-06

IEC 62443

3-3 SR 2.11

BSI IT-Grundschutz

OPS.1.1.5

ANSSI

Hygiene.29SecNumCloud.13.7

FINMA Circular 2023/1

IV.A(28)IV.C(66)

OSFI B-13

B-13.3.3

EU GDPR

Art.33(1)

EU DORA

Art.10(1)

BIO2

8.158.17

RBI CSF

Annex1.17

FISC Security Guidelines

FISC.O11

MLPS 2.0

8.1.4.3

EU CRA

CRA.I.2l

NCA ECC

2-12

UAE IA

T7

CBB TM

TM-12

Qatar NIA

OS

CBUAE

CR-3

CBE CSF

CD-1

SA JS2

JS2-7.3

CBN CSF

Part3.5

BoG CISD

CISD-VII

BoM CTRM

4.2

IOSCO Cyber Resilience

DET-1

BCBS 239

Principle 5

FFIEC IS

III.B

NYDFS 500

500.6

HIPAA Security Rule

§164.312(b)

EBA ICT Guidelines

3.4.53.5(c)

SEBI CSCRF

DE.AU

CMMC 2.0

AU

10 CFR 73.54

RG5.71-A-AU

Common Criteria

CC Part 2 — FAU

Lloyd's Minimum Standards

MS8.12

NAIC Insurance Data Security

4-audit

PRA SS1/23

P-IT.2

HITRUST CSF v11

09.g

FDA 21 CFR Part 11

§11.10(e)

FDA Cybersecurity Guidance

SA-5

ISO 27799

12.4

SEC Custody (Digital Assets)

SEC-CD-15

ISO 17799 (legacy)

10.10.6

COBIT 4.1 (legacy)

None.