1.3.1.2 Ensure AppArmor is enabled

Information

AppArmor is a kernel enhancement to confine programs to a limited set of resources. AppArmor is enabled by default.

Note: This recommendation is designed around the grub bootloader, if LILO or another bootloader is in use in your environment enact equivalent settings.

AppArmor is a security mechanism and disabling it is not recommended.

Solution

Edit /etc/default/grub of file in /etc/default/grub.d and remove the apparmor=0 parameters to the GRUB_CMDLINE_LINUX= line

Run the following commands to update the grub2 configuration and reboot the system:

# update-grub
# reboot

See Also

https://workbench.cisecurity.org/benchmarks/24330

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 68ee636c79581b4eace94bbb86a1593f7e18df556d402498c34c6d4363ab18c1