# Cis Ubuntu1804 V220 2 1 2 3

> Ensure chrony is enabled and running

- Skill: `cyberstrikeus/cis-ubuntu1804-v220-2-1-2-3` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-ubuntu1804-v220-2-1-2-3`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-ubuntu1804-v220-2-1-2-3/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-ubuntu1804-v220-2-1-2-3

---


# 2.1.2.3 Ensure chrony is enabled and running (Automated)

## Profile

- Level 1 - Server
- Level 1 - Workstation

## Description

chrony is a daemon for synchronizing the system clock across the network.

## Rationale

chrony needs to be enabled and running in order to synchronize the system to a timeserver.

Time synchronization is important to support time sensitive security mechanisms and to ensure log files have consistent time records across the enterprise to aid in forensic investigations.

## Audit Procedure

### Command Line

IF chrony is in use on the system, run the following commands:

Run the following command to verify that the chrony service is enabled:

```bash
# systemctl is-enabled chrony.service
enabled
```

Run the following command to verify that the chrony service is active:

```bash
# systemctl is-active chrony.service
active
```

## Expected Result

- `systemctl is-enabled chrony.service` returns `enabled`
- `systemctl is-active chrony.service` returns `active`

## Remediation

### Command Line

IF chrony is in use on the system, run the following commands:

Run the following command to unmask chrony.service:

```bash
# systemctl unmask chrony.service
```

Run the following command to enable and start chrony.service:

```bash
# systemctl --now enable chrony.service
```

OR

If another time synchronization service is in use on the system, run the following command to remove chrony:

```bash
# apt purge chrony
```

## References

1. NIST SP 800-53 Rev. 5: AU-8

## CIS Controls

- v8: 8.4 - Standardize Time Synchronization
- v7: 6.1 - Utilize Three Synchronized Time Sources

