SELinux must be enabled and in enforcing mode. Rationale: The mandatory access controls provided by the default SELinux policy are a critical mechanism to prevent containers from accessing sensitive data or modifying system files that belong to the host or to other containers.