GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INF-014 Clock Synchronisation

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

All production systems synchronise their clocks from approved, authoritative time sources (e.g., NTP servers). Clock drift is monitored and corrected. Accurate timestamps are critical for log correlation, audit trails, and incident investigations.

Rationale

Skewed clocks break log correlation across distributed systems, making incident investigation and compliance evidence unreliable.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (7)

LOG-06Clock Synchronizationfull
LOG-06Clock Synchronizationfull
8.17Clock synchronizationfull
NIS2-CIR-3.2Monitoring and Logginginformative
AU-8Time Stampsfull
SC-45System Time Synchronizationfull
SC-45(1)System Time Synchronization | Synchronization with Authoritative Time Sourcefull

Evidence (2)

configurationtechnicalautomated

NTP configuration for all production systems showing synchronisation to approved, authoritative time sources with drift monitoring enabled.

Example: AWS CloudFormation or Terraform configuration showing NTP settings for EC2 instances (e.g., Amazon Time Sync Service), or equivalent time synchronisation configuration export for the production environment

Test: Read the time synchronisation configuration across a representative sample of production systems. Verify: (1) every sampled system references an authoritative time source named in the organisation's standard, (2) no sampled system uses an unapproved source, (3) drift monitoring is enabled and an alert is configured against a stated offset threshold, (4) the measured offset read from the time synchronisation client on each sampled host is within that threshold, (5) systems that cannot be sampled are named rather than assumed compliant.

logtechnicalautomated

NTP synchronisation logs or monitoring alerts confirming clock drift is detected and corrected across production systems.

Example: CloudWatch metric or equivalent monitoring alert history showing NTP drift metric values for production instances over the last 30 days, with any out-of-threshold events and their resolution

Test: Query the monitoring platform for NTP drift metrics over the last 30 days. Verify: (1) drift metrics are being collected from all in-scope production systems; (2) any drift exceeding the defined threshold generated an alert; (3) alerts were actioned within the defined response window.

Questions (2)

boolean

Do all production systems synchronise their clocks from approved, authoritative time sources?

Cloud-native environments should use the cloud provider's time sync service (e.g. Amazon Time Sync Service, Google Time Servers). Drift monitoring should alert on offsets exceeding a defined threshold.

select

How is NTP synchronisation and clock drift monitored across production systems?

Automated monitoring with alerting on clock drift exceeding a defined threshold (e.g. >1 second)Cloud provider time sync configured by default: no explicit monitoring beyond provider guaranteesPeriodic manual check of NTP configuration on a sample of systemsNo monitoring of clock synchronisation

Automated drift monitoring with alerts is expected for environments where log correlation accuracy is required for compliance or incident response. Cloud provider defaults alone are insufficient.