1.3.1.2 Ensure AppArmor is enabled

Information

AppArmor is a kernel enhancement to confine programs to a limited set of resources. AppArmor is enabled by default.

AppArmor is a security mechanism and disabling it is not recommended.

Solution

Edit /etc/default/grub or a file in /etc/default/grub.d and remove the apparmor=0 parameter from the GRUB_CMDLINE_LINUX= line.

Run the following commands to update the grub configuration and reboot the system:

# update-grub
# reboot

See Also

https://workbench.cisecurity.org/benchmarks/27797

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: cf2634b9ee4e6a0482e57d4d080078e3d7ce3f6abd6620ffb4aa43fa06057d9b