GEN000000-LNX00800 - The system must use a Linux Security Module configured to limit the privileges of system services - 'SELINUX = enforcing'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Linux Security Modules such as SELinux and AppArmor can be used to provide protection from software exploits by explicitly defining the privileges permitted to each software package.

Solution

Enable one of the SELinux policies.
Edit /etc/sysconfig/selinux and set the value of the SELINUX option to 'enforcing' and SELINUXTYPE to 'targeted' or 'strict'.
Restart the system.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(3), CAT|III, CCI|CCI-000366, Rule-ID|SV-63085r1_rule, STIG-ID|GEN000000-LNX00800, Vuln-ID|V-22584

Plugin: Unix

Control ID: 40a49ea40713daa00b4872a824663fe5a5590d568105525cce732e598c8d2e72