Amazon Linux 2023 chronyd service must be enabled.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-274023AZLX-23-001055SV-274023r1120057_ruleCCI-004923medium
Description
Inaccurate time stamps make it more difficult to correlate events and can lead to an inaccurate analysis. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. Sources outside the configured acceptable allowance (drift) may be inaccurate.
STIGDate
Amazon Linux 2023 Security Technical Implementation Guide2026-02-27

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · V1R3 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-004923
1.00
  • DISA · V1R3 · disa_xccdf · related

Details

Check Text (C-274023r1120057_chk)

Verify Amazon Linux 2023 has the chronyd service set to active with the following command: $ systemctl is-active chronyd active If the chronyd service is not active, this is a finding.

Fix Text (F-78019r1120056_fix)

Configure Amazon Linux 2023 to have the chronyd service set to active with the following command: $ sudo systemctl enable --now chronyd