{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Framework - ISO 27001 (Cyber)","title":"Episode 62 — A.8.17–8.18 — Clock synchronization; Privileged utility programs","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/9eb8e345\"></iframe>","width":"100%","height":180,"duration":1319,"description":"A.8.17 mandates synchronized time across systems so that events recorded in different places can be reliably correlated. For the exam, stress why this matters: investigations, non-repudiation, and regulatory reporting all depend on consistent, traceable timestamps. Organizations typically standardize on secure time sources (e.g., authenticated NTP or cloud time services), designate stratum hierarchies, protect time infrastructure from spoofing, and monitor drift with thresholds that trigger correction. Time settings must align to logging and monitoring strategies, with clear documentation of time zones, daylight-savings handling, and retention of configuration changes. Candidates should highlight how unsynchronized clocks undermine evidence chains, create false sequences in incident timelines, and complicate SLA verification; therefore, clock control is not an afterthought but a foundational integrity requirement for the whole telemetry fabric.\nA.8.18 covers privileged utility programs—powerful tools like debuggers, packet sniffers, firmware flashers, database consoles, and hypervisor or cloud administrative utilities that can bypass normal controls. The control expects tight governance: inventory and classification of such utilities, restricted installation and execution, approved use cases, and monitoring of invocation with full command and parameter capture where feasible. Technical enforcement may include application allow-listing, PAM-mediated launch, sandboxed consoles, and dedicated privileged workstations. Pitfalls include leaving diagnostic tools on production hosts, unmanaged portable binaries, and “break-glass” accounts with access to everything but no session recording. Strong programs pair least privilege with just-in-time elevation, segregate admin networks, and require change or incident tickets to justify use, with post-use reviews to ensure necessity and proportionality. Candidates should connect time integrity and privileged utility control to...","thumbnail_url":"https://img.transistorcdn.com/QyFhFvukwf4vQ5PJ2PWS6N0cGlZo_HHhOwGBe1ETB4E/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82ZTEw/YzQ0MTcxYzBiYmVi/NjgyOWYzMTRiZjk5/NDhjNS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}