PCI DSS Security Maturity Model·AWS v1.0.0
Quick Wins Infrastructure Protection 🤝 Shared

r10.3 Reliable time synchronization (10.6)

Ensure that system clocks are synchronized with a reliable time source so that log timestamps are consistent and trustworthy.

Quick Wins
Foundational
Efficient
Optimized
Effort: Low Impact: Medium Applies to CDE: Yes

AWS services

Amazon Time Sync Service Amazon EC2

Requirement 10

Log and Monitor All Access to System Components and Cardholder Data

PCI sub-requirements covered

  • 10.6 Time-synchronization mechanisms support consistent time settings

How to implement on AWS

Use the Amazon Time Sync Service (NTP at 169.254.169.123) on all EC2 instances. Restrict who can modify the time configuration. Verify synchronization centrally. AWS managed services already use synchronized time.

Practical implementation

How this control is implemented in each reference architecture:

Use the Amazon Time Sync Service on all EC2 instances and restrict who can change time settings in the account.

Single-account, 3-tier →

Standardize the Amazon Time Sync Service across all account baselines (Control Tower/IaC), so every CDE account uses a consistent, reliable time source.

Multi-account with a dedicated PCI OU →

PCI validation

Testing methods: examineobserve

Testing procedures

  • Examine configuration settings to verify time-synchronization technology is implemented and kept current (10.6.1).
  • Examine configurations for acquiring, distributing, and storing correct time (10.6.2), and verify access to time data is restricted and changes to time settings on critical systems are logged, monitored, and reviewed (10.6.3.a, 10.6.3.b).

Evidence in AWS

  • Amazon Time Sync Service configuration on in-scope instances.
  • Permission restrictions for changing the time configuration.
  • Evidence of clock synchronization across system components.

Customized approach

Requires a targeted risk analysis (Req 12.3.2).

Customized Approach Objective

  • 10.6 — Common time is established across all systems.

Learning resources

References

  • PCI DSS v4.0.1 Requirement 10.6