1.4.2 Set the SELinux State - SELINUX=enforcing

Information

Set SELinux to enable when the system is booted.

Rationale:

SELinux must be enabled at boot time in to ensure that the controls it provides are in effect at all times.

Solution

Edit the /etc/selinux/config file to set the SELINUX parameter:

SELINUX=enforcing

Default Value:

OS Default: No

See Also

https://workbench.cisecurity.org/files/3096

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CSCv7|14.6

Plugin: Unix

Control ID: 5e037306155d4fac0b55d883cb347fafba31b6771ad9099175a733a7c4d2215f