RHEL 9 fapolicy module must be enabled.
DISA Rule
SV-258090r958808_rule
Vulnerability Number
V-258090
Group Title
SRG-OS-000370-GPOS-00155
Rule Version
RHEL-09-433015
Severity
CAT II
CCI(s)
- CCI-001764 - Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage.
- CCI-001774 - Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system.
Weight
10
Fix Recommendation
Enable the fapolicyd with the following command:
$ systemctl enable --now fapolicyd
Check Contents
Verify that RHEL 9 fapolicyd is active with the following command:
$ systemctl is-active fapolicyd
active
If fapolicyd module is not active, this is a finding.
Vulnerability Number
V-258090
Documentable
False
Rule Version
RHEL-09-433015
Severity Override Guidance
Verify that RHEL 9 fapolicyd is active with the following command:
$ systemctl is-active fapolicyd
active
If fapolicyd module is not active, this is a finding.
Check Content Reference
M
Target Key
5551