1.3.1.2 Ensure AppArmor is enabled

Information

AppArmor is a kernel enhancement to confine programs to a limited set of resources. AppArmor is enabled by default.

AppArmor is a security mechanism and disabling it is not recommended.

Solution

Edit /etc/default/grub or a file in /etc/default/grub.d and remove the apparmor=0 parameter from the GRUB_CMDLINE_LINUX= line.

Run the following commands to update the grub configuration and reboot the system:

# update-grub
# reboot

See Also

https://workbench.cisecurity.org/benchmarks/27798

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 51d067fa73ee5165ffc9046a0de571ae0cd388efcdefb5e8d2fc200c56a4c232