Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.17

Clock Synchronization: A Practical Implementation Guide

Keep system clocks accurate and consistent so logs, transactions and investigations can be trusted.

This control concerns synchronizing clocks of information-processing systems to approved time sources.

Practical interpretation: Time supports authentication, certificates, distributed processing and evidence. Sources, hierarchy, security, drift monitoring and time zones must be managed.

What should the control achieve?

  • Approved authoritative time sources are defined.
  • Systems synchronize through resilient hierarchy.
  • Drift and synchronization failures are detected.
  • Logs use consistent timestamp conventions.

Step-by-step implementation

1

Define time standard

Select UTC or documented conventions and approved authoritative sources.

2

Design hierarchy

Use trusted internal servers or authenticated services with redundancy.

3

Configure systems

Cover servers, network, cloud, applications, appliances and security tools.

4

Secure synchronization

Restrict configuration and use protected protocols where supported.

5

Monitor drift

Alert on source loss, excessive offset and conflicting time.

6

Validate evidence

Test timestamps across correlated events and daylight changes.

What this could look like in practice

Infrastructure uses two internal time servers synchronized to independent trusted sources. Critical systems alert when drift exceeds threshold, and logs store UTC while interfaces show local time.

ActivityPractical implementationEvidence
Time sourceApproved redundant source supplies internal servers.Configuration
Endpoint syncManaged policy points devices to hierarchy.Compliance report
Drift alertOffset beyond threshold creates incident ticket.Alert
InvestigationEvents correlate across cloud and endpoint systems.Timeline

Implementation evidence

  • Time standard
  • Source inventory
  • NTP configuration
  • Access restrictions
  • Drift monitoring
  • Failure alerts
  • Correlation tests
  • Exception records

Useful metrics

  • Systems within drift threshold
  • Synchronization failures
  • Unknown time sources
  • Critical devices not monitored

Common mistakes

  • Using arbitrary public time servers.
  • Ignoring appliances and applications.
  • Mixing local time and UTC without clarity.
  • No alert when synchronization fails.
  • Allowing administrators to alter time silently.

Questions an auditor may ask

  • Which sources are authoritative?
  • How is time hierarchy protected?
  • Show a drift alert.
  • How are time zones handled in investigations?
Implementation test: Compare timestamps for one transaction across endpoint, identity, network, application and cloud logs.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.