Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SC

SC-45System Time Synchronization

Synchronize system clocks within and between systems and system components.

Last updated: 20 August 2026 20:22 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (4)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-295Improper Certificate Validation1,700+Correct system time is required for proper enforcement of certificate notBefore/notAfter dates and time-based revocation checks.
CWE-345Insufficient Verification of Data Authenticity800+Time synchronization supports reliable freshness verification when checking data authenticity across systems or components.
CWE-613Insufficient Session Expiration600+Consistent clocks across systems allow session expiration and timeout enforcement to function as intended in distributed environments.
CWE-294Authentication Bypass by Capture-replay300+Accurate synchronized time enables tight timestamp windows that directly limit capture-replay windows in authentication protocols.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9