Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SC

SC-45System Time Synchronization

Synchronize system clocks within and between systems and system components.

Last updated: 19 May 2026 14:18 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (4)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-295Improper Certificate Validation1,606Correct system time is required for proper enforcement of certificate notBefore/notAfter dates and time-based revocation checks.
CWE-345Insufficient Verification of Data Authenticity654Time synchronization supports reliable freshness verification when checking data authenticity across systems or components.
CWE-613Insufficient Session Expiration613Consistent clocks across systems allow session expiration and timeout enforcement to function as intended in distributed environments.
CWE-294Authentication Bypass by Capture-replay266Accurate synchronized time enables tight timestamp windows that directly limit capture-replay windows in authentication protocols.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-40093 UPD1.68.10.0008partial

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9