PCI DSS 10.6.1: System clocks and time are synchronized using time-synchronization technology

PCI DSS v4.0.1 control 10.6.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 10.6.

Requirement 10: Log and Monitor All Access to System Components and Cardholder Data › Section 10.6

System clocks and time are synchronized using time-synchronization technology.

Summary

Clocks are synchronised, so events from different systems can be put in order.

What the assessor will examine

These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.

Procedure
10.6.1 Examine system configuration settings to verify that time-synchronization technology is implemented and kept current.

Mechanically simple and consequentially large: without it, correlating a firewall entry with an application entry during an incident is guesswork, and every log-based control above it inherits the ambiguity. It is also the control an assessor can check in seconds by comparing two systems. The sub-controls that follow govern where the time comes from and how it is protected, because a synchronised clock taking its time from an untrusted source is synchronised to whatever that source says.

What to prepare

  • The time source configuration for each system component.
  • Evidence clocks agree, sampled across components.
  • The controls on the time source itself, per 10.6.2 and 10.6.3.

How to implement it

1. Use one internal source, fed from a trusted external one. It gives you a single place to protect and a single answer when systems disagree.

2. Check drift, do not assume it. A configured NTP client that cannot reach its server drifts silently, and the symptom appears months later in an investigation.

3. Log in UTC and render locally. Mixed local times with daylight saving make correlation harder than no timestamps at all, because the errors are plausible.

4. Include the appliances. Switches, firewalls and out-of-band controllers are the components most likely to be unsynchronised and among the most important to correlate.

Where this commonly fails

  • NTP configured and blocked by egress rules, so it never syncs.
  • Network devices and appliances left unsynchronised.
  • Mixed time zones across log sources, making ordering unreliable.
  • Time taken directly from an external source with no control over it.

Others in section 10.6:

Control What it requires
10.6.2 Systems are configured to the correct and consistent time…
10.6.3 Time synchronization settings and data are protected…

10.5.1 · All controls · 10.6.2

Source

The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.

The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.