AU-8 Time stamps
Requires audit record time stamps to be produced from internal system clocks at an organization-defined granularity, and expressed in Coordinated Universal Time or with a fixed or recorded local offset so records from di
4
artefacts
3
held by a system
1
at each review
easy
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Time synchronisation configuration and authoritative time source for in scope systems · Cloud console / configuration management
- Sample records from several systems showing consistent time reference · Policy repository / GRC workspace
- Monitoring or drift report for clock synchronisation failures · SIEM / log platform
periodic reviewEvidence produced at each review
- Defined time granularity requirement and evidence it is met · Policy repository / GRC workspace
governing documentDocuments that govern the control
none for this control
First move
Automate the pull from your Cloud console / configuration management. Configuration snapshots and change history from the cloud console or IaC repository, diffed against the baseline.
Common gaps auditors find
- Some systems log in local time with no offset, breaking cross system correlation
- Time source unauthenticated or set per device, so drift goes undetected
- Granularity too coarse to order events that occur within the same second
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetAU-7 Audit record reduction and report generation · AU-9 Protection of audit information