CIS Ubuntu 14.04 LTS - 1.6.1.3 Ensure SELinux policy is configured

Verify that SELinux policy is configured to meet or exceed the default targeted policy

cyberstrikeus Updated

File contents

1.6.1.3 Ensure SELinux policy is configured (Scored)

Profile Applicability

  • Level 2 - Server
  • Level 2 - Workstation

Description

Configure SELinux to meet or exceed the default targeted policy, which constrains daemons and system software only.

Rationale

Security configuration requirements vary from site to site. Some sites may mandate a policy that is stricter than the default policy, which is perfectly acceptable. This item is intended to ensure that at least the default recommendations are met.

Audit Procedure

Run the following commands and ensure output matches "ubuntu", "default" or "mls":

grep SELINUXTYPE= /etc/selinux/config
sestatus

Expected Result

SELINUXTYPE=ubuntu

Policy from config file: ubuntu

Remediation

Edit the /etc/selinux/config file to set the SELINUXTYPE parameter:

SELINUXTYPE=ubuntu

Default Value

Not applicable.

Notes

If your organization requires stricter policies, ensure that they are set in the /etc/selinux/config file.

References

  • CIS Controls: 14.4 Protect Information With Access Control Lists

Profile

  • Level 2 - Server
  • Level 2 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-14-04-lts-benchmark-v2/cis-ubuntu1404-v210-1-6-1-3 commit 433140cc4a

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu-14-04-lts-1-6-1-3-ensure-selinux-policy-is-config