r10.3 Reliable time synchronization (10.6)
Ensure that system clocks are synchronized with a reliable time source so that log timestamps are consistent and trustworthy.
AWS services
Requirement 10
Log and Monitor All Access to System Components and Cardholder Data
PCI sub-requirements covered
- 10.6 Time-synchronization mechanisms support consistent time settings
How to implement on AWS
Use the Amazon Time Sync Service (NTP at 169.254.169.123) on all EC2 instances. Restrict who can modify the time configuration. Verify synchronization centrally. AWS managed services already use synchronized time.
Practical implementation
How this control is implemented in each reference architecture:
Use the Amazon Time Sync Service on all EC2 instances and restrict who can change time settings in the account.
Single-account, 3-tier →Standardize the Amazon Time Sync Service across all account baselines (Control Tower/IaC), so every CDE account uses a consistent, reliable time source.
Multi-account with a dedicated PCI OU →PCI validation
Testing procedures
- Examine configuration settings to verify time-synchronization technology is implemented and kept current (10.6.1).
- Examine configurations for acquiring, distributing, and storing correct time (10.6.2), and verify access to time data is restricted and changes to time settings on critical systems are logged, monitored, and reviewed (10.6.3.a, 10.6.3.b).
Evidence in AWS
- Amazon Time Sync Service configuration on in-scope instances.
- Permission restrictions for changing the time configuration.
- Evidence of clock synchronization across system components.
Customized approach
Requires a targeted risk analysis (Req 12.3.2).
Customized Approach Objective
- 10.6 — Common time is established across all systems.
Learning resources
References
- PCI DSS v4.0.1 Requirement 10.6
PCI DSS Security Maturity Model