ISO 27001A.8 — Clock synchronization
A.8.17
Clock synchronization
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Synchronize clocks of information processing systems to approved time sources.
Points of focus
- Standard time source
- Configure all systems
- Monitor drift
- Document exceptions
Implementation notes
Enforce time sync via cloud image defaults or config management. Prefer vendor time services. Alert on drift. Remember serverless inherits provider time — document that. Assign a named owner in the SoA, tie operating evidence to ntp/chrony configuration baseline, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Show baseline config and sample hosts with synchronized clocks; explain serverless inheritance.
Evidence auditors typically request:
- NTP/chrony configuration baseline
- Config management policy enforcing time sync
- Alerting on clock drift
- Image/golden AMI settings
Common gaps
- App servers hours off
- Container hosts not synced
- Auth token skew failures ignored
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.17 | This control |
| SOC 2 | CC7.2 | Related SOC 2 themes (CC7.2) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.17)
Frequently Asked Questions
Log correlation and access reviews depend on trustworthy timestamps.
Store UTC; display local as needed.
Ensure your collectors and sources agree; document provider responsibility.
Even without owned data centers, clock synchronization still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with ntp/chrony configuration baseline, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.