1.6.2.1 Ensure AppArmor is not disabled in bootloader configuration - /boot/grub/menu.lst apparmor=0

Information

AppArmor must be enabled at boot time in your bootloader configuration to ensure that the controls it provides are not overridden.

Solution

For grub based systems edit /boot/grub/menu.lst and remove all instances of apparmor=0 on all kernel lines.

See Also

https://workbench.cisecurity.org/files/1856