Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SC

SC-45System Time Synchronization

Synchronize system clocks within and between systems and system components.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (4)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-295Improper Certificate Validation1,586Correct system time is required for proper enforcement of certificate notBefore/notAfter dates and time-based revocation checks.
CWE-345Insufficient Verification of Data Authenticity643Time synchronization supports reliable freshness verification when checking data authenticity across systems or components.
CWE-613Insufficient Session Expiration606Consistent clocks across systems allow session expiration and timeout enforcement to function as intended in distributed environments.
CWE-294Authentication Bypass by Capture-replay264Accurate synchronized time enables tight timestamp windows that directly limit capture-replay windows in authentication protocols.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-400931.68.10.0007partial

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9