1.3.1.2 Ensure AppArmor is enabled

Information

AppArmor is a kernel enhancement to confine programs to a limited set of resources. AppArmor is enabled by default.

Note: This recommendation is designed around the grub bootloader, if LILO or another bootloader is in use in your environment enact equivalent settings.

AppArmor is a security mechanism and disabling it is not recommended.

Solution

Edit /etc/default/grub of file in /etc/default/grub.d and remove the apparmor=0 parameters to the GRUB_CMDLINE_LINUX= line

Run the following commands to update the grub2 configuration and reboot the system:

# update-grub
# reboot

See Also

https://workbench.cisecurity.org/benchmarks/24932

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: cf2634b9ee4e6a0482e57d4d080078e3d7ce3f6abd6620ffb4aa43fa06057d9b