ISO/IEC 27001:2022 Annex A · Control 8.17
Clock Synchronization: A Practical Implementation Guide
Keep system clocks accurate and consistent so logs, transactions and investigations can be trusted.
This control concerns synchronizing clocks of information-processing systems to approved time sources.
What should the control achieve?
- Approved authoritative time sources are defined.
- Systems synchronize through resilient hierarchy.
- Drift and synchronization failures are detected.
- Logs use consistent timestamp conventions.
Step-by-step implementation
Define time standard
Select UTC or documented conventions and approved authoritative sources.
Design hierarchy
Use trusted internal servers or authenticated services with redundancy.
Configure systems
Cover servers, network, cloud, applications, appliances and security tools.
Secure synchronization
Restrict configuration and use protected protocols where supported.
Monitor drift
Alert on source loss, excessive offset and conflicting time.
Validate evidence
Test timestamps across correlated events and daylight changes.
What this could look like in practice
Infrastructure uses two internal time servers synchronized to independent trusted sources. Critical systems alert when drift exceeds threshold, and logs store UTC while interfaces show local time.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Time source | Approved redundant source supplies internal servers. | Configuration |
| Endpoint sync | Managed policy points devices to hierarchy. | Compliance report |
| Drift alert | Offset beyond threshold creates incident ticket. | Alert |
| Investigation | Events correlate across cloud and endpoint systems. | Timeline |
Implementation evidence
- Time standard
- Source inventory
- NTP configuration
- Access restrictions
- Drift monitoring
- Failure alerts
- Correlation tests
- Exception records
Useful metrics
- Systems within drift threshold
- Synchronization failures
- Unknown time sources
- Critical devices not monitored
Common mistakes
- Using arbitrary public time servers.
- Ignoring appliances and applications.
- Mixing local time and UTC without clarity.
- No alert when synchronization fails.
- Allowing administrators to alter time silently.
Questions an auditor may ask
- Which sources are authoritative?
- How is time hierarchy protected?
- Show a drift alert.
- How are time zones handled in investigations?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.