2.1.4 Ensure Trusted Execution (TE) policies are locked

Information

Set trusted execution policy LOCK_KERN_POLICIES to enabled. All of the other policies will then be locked and cannot be changed without disabling the LOCK_KERN_POLICIES policy and then restarting the system.

When policies are locked, unauthorized users cannot make changes to the policies to allow them to execute unapproved tools and then revert the settings afterwards. An unplanned system reboot is likely to be noticed and investigated

Solution

Execute the following command

trustchk -p LOCK_KERN_POLICIES=ON

Impact:

To revert this setting and/or to be able to make modifications this policy must first be switched off using trustchk -p LOCK_KERN_POLICIES=OFF followed by a reboot

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 6a621cbe9c7f548492b862056eccdce5be41721a0b806cbcd68a7ede7d371c31