A.8.17 Technological
Clock synchronization
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (6)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-8fullcovers — Both controls establish a single authoritative time source and enforce synchronization across systems so that audit and event records carry consistent, reliable timestamps.
- SC-45mostlyaligns with — The ISO requirement to synchronize all systems to a trusted reference clock directly supports the NIST objective of maintaining accurate system time across the enterprise.
- AU-12partialaligns with — Accurate, synchronized clocks are a prerequisite for generating comparable and trustworthy audit records, which AU-12 relies upon.
- AU-6partialaligns with — Reliable timestamps produced by clock synchronization enable effective correlation and review of audit records during analysis and reporting activities.
Aligned NIST CSF 2.0 outcomes (8)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.PS-04mostlyaligns with — Synchronized, accurate time sources are a prerequisite for generating reliable log records that can be used for continuous monitoring and later analysis.
- DE.AE-02partialaligns with — Reliable time-stamps allow analysts to reconstruct the sequence and timing of activities associated with potentially adverse events.
- DE.AE-03partialaligns with — Consistent timestamps across systems enable correlation of event data from multiple sources during adverse-event analysis.
- GV.OC-03partialaligns with — Documenting and meeting external legal, regulatory, and contractual requirements for accurate time representation directly supports compliance obligations.
- ID.RA-07partialaligns with — Tracking clock variance between cloud and on-premises environments provides a measurable input for assessing risk impact of configuration changes or exceptions.
Related OWASP ASVS 5.0 requirements (3)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V16.2.2fullaligns with — Both require synchronized, trusted time sources so that security event timestamps remain accurate and comparable across systems for investigation and correlation.
- V16.2.1partialaligns with — Reliable clock synchronization underpins the completeness and accuracy of the metadata (when, where, who, what) that must be captured in each log entry.
Related weaknesses / CWE (8)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-778partialmitigates — Trustworthy timestamps ensure that security-relevant events are recorded with accurate chronology, improving the usefulness of logs for detecting and investigating incidents.
- CWE-203nonenone — Accurate, synchronized timestamps reduce observable timing discrepancies that an attacker could exploit to infer sensitive information or distinguish between success and failure paths.
- CWE-208nonenone — Consistent reference clocks limit the attacker's ability to measure or manipulate timing differences that could reveal internal state or processing paths.
- CWE-222nonenone — Clock synchronization supports accurate timestamps but does not prevent truncation of log content.
- CWE-341nonenone — Accurate time sources limit one observable state vector but do not address broader predictability.
- CWE-360nonenone — Clock synchronization supports event correlation but does not prevent spoofed event data.
- CWE-367nonenone — Reliable, synchronized time across systems narrows the exploitable window in which a resource state can change between a security check and its use.
Mitigated MITRE ATT&CK techniques (3)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1070partialmitigates — Consistent, trusted timestamps across logs and systems limit an adversary’s ability to erase or obscure evidence of their actions without leaving detectable timing anomalies.
- T1070.006nonemitigates — Accurate, synchronized timestamps make it harder for an adversary to alter file or event times without creating detectable inconsistencies across multiple systems.
- T1556nonemitigates — Reliable time sources reduce the chance that an attacker can successfully replay or forge time-based authentication tokens and session material.
Prevented OWASP Web Top 10 (2025) risks (1)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A09partialprevents — Accurate, synchronized timestamps across systems enable reliable correlation of events, allowing security teams to detect and respond to incidents that would otherwise be obscured by timing discrepancies.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.