The Mainframe Products must use internal system clocks to generate time stamps for audit records.

STIG ID: SRG-APP-000116-MFP-000171  |  SRG: SRG-APP-000116 |  Severity: medium |  CCI: CCI-000159 |  Vulnerability Id: V-205476 | 

Vulnerability Discussion

Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events.

If the internal clock is not used, the system may not be able to provide time stamps for log messages. Additionally, externally generated time stamps may not be accurate. Applications can use the capability of an operating system or purpose-built module for this purpose.

Check

Examine installation and configuration settings.

If the Mainframe Product does not use the z/OS system clock for audit time stamps, this is a finding.

Fix

Configure the Mainframe Product to use the z/OS system clock for audit time stamps.