← PCI DSS 4.0.1 · Req 10 — Log and monitor

10.6 — Time synchronisation

low loggingintegrity

Requirement

System clocks and time are synchronised using time-synchronisation technology, from designated time servers receiving time from industry-accepted sources, with time data protected and changes logged.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
time synchroni…time syncntpclock synchroni…clocks are synchroni…chrony
Required element 2 — any one of
synchroni…time servertime serversntpsource
Supporting terms — specificity signals
10.6.110.6.210.6.3utc

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.5(1)(d) Accuracy integrity
GDPR Art.16 Right to rectification integrity
CCPA/CPRA 1798.106 Right to correct integrity
SOC 2 CC2.1 Quality information for internal control logging
SOC 2 PI1.1 Quality information about processing objectives and specifications integrity
ISO 27001 A.8.15 Logging logging
HIPAA 164.312(b) Audit controls (R) logging
HIPAA 164.312(c)(1) Integrity (R/A) integrity