Skip to content
arrow_back
search
Annex A 8.17 verified ISO/IEC 27001:2022

Clock synchronization for information systems

Ensure all system clocks are set to the same time source to aid in event tracking and investigations.

record_voice_over

Plain language

This control is about making sure all the clocks on your organisation's computers and systems are set to the exact same time. This consistency helps when you need to track what happened and when, especially if you're investigating an incident or resolving a dispute. If the clocks are off, it can be hard to prove the sequence of events, which can cause issues with accountability or legal matters.

Framework

ISO/IEC 27001:2022

Control effect

Detective

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

The clocks of information processing systems used by the organization shall be synchronized to approved time sources.
verified ISO/IEC 27001:2022 Annex A 8.17
priority_high

Why it matters

Unsynchronised system clocks hinder accurate log/event correlation, weakening investigations, audit trails and incident response timing.

settings

Operational notes

Configure NTP on all hosts to approved time sources; monitor drift (eg <100 ms) and alert on offsets or NTP failures.

Mapping detail

Mapping

Direction

Controls