CLAUDE CODE MARKETPLACES
SkillsCyberStrikeus/CyberStrikeAU-8(2)_secondary-authoritative-time-source

AU-8(2)_secondary-authoritative-time-source

Secondary Authoritative Time Source

npx skills add https://github.com/CyberStrikeus/CyberStrike --skill AU-8(2)_secondary-authoritative-time-source
SKILL.md

AU-8(2) Secondary Authoritative Time Source

Enhancement of: AU-8

High-Level Description

Family: Audit and Accountability (AU) Framework: NIST SP 800-53 Rev 5

No description available.

What to Check

  • Verify AU-8(2) Secondary Authoritative Time Source is documented in SSP
  • Confirm control is operating effectively
  • Review evidence of continuous monitoring for AU-8(2)
  • Verify enhancement builds upon base control AU-8

How to Test

Step 1: Review Documentation

Examine the System Security Plan (SSP) and related artifacts for AU-8(2) implementation details. Verify the organization has documented how this control is satisfied.

Step 2: Validate Implementation

# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly

# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null

Step 3: Test Operating Effectiveness

Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.

Tools

ToolPurposeUsage
cloud-audit-mcpCheck logging configurationcloud_audit_logging
AWS CLIReview CloudTrail/CloudWatchaws cloudtrail describe-trails

Remediation Guide

Control Statement

Refer to NIST SP 800-53 Rev 5 for the full control statement.

Implementation Guidance

Implement this control per organizational risk assessment and system categorization.

Risk Assessment

FindingSeverityImpact
AU-8(2) Secondary Authoritative Time Source not implementedMediumAudit and Accountability
AU-8(2) partially implementedLowIncomplete Audit and Accountability

CWE Categories

CWE IDTitle
CWE-778Insufficient Logging

References

Checklist

  • Control documented in SSP
  • Implementation evidence collected
  • Operating effectiveness validated
  • Continuous monitoring in place
  • Related controls (none) reviewed