We're setting up a card processing service on Amazon AWS, and were wondering whether the AWS Time Sync service could be incorporated without running afoul of the PCI time sync requirements?
Specifically, the requirements talk about all hosts, services, etc. synchronizing to a service hosted internal to the network, and that the internal NTP service is the only thing allowed to talk to external time sources.
I don't see the Time Sync Service listed on Amazon's list of "in-scope services" nor have I found anything on AWS re. Time Sync and PCI.