Why is time synchronization critical for PCI DSS logging?
- A.It improves system performance, because intrusion detection at the CDE perimeter replaced the audit logging requirements
- B.It prevents clock drift on servers, which matches v4.0's position that centralized logging is needed only for internet-facing components, with internal systems permitted to keep local logs that are never reviewed
- C.Synchronized clocks ensure accurate timestamps across all systems, enabling proper log correlation and forensic analysis
- D.Time sync is only for scheduling, given that the standard exempts the logging infrastructure itself from access controls
Why C is correct
Time synchronization ensures that logs from different systems have consistent, accurate timestamps, which is essential for correlating events across systems during incident investigation.
Know someone studying for PCI DSS? Send them this one.