SV-270660r1066469_rule
V-270660
SRG-OS-000368-GPOS-00154
UBTU-24-100510
CAT II
10
Enable "apparmor" with the following command:
$ sudo systemctl enable apparmor.service
Start "apparmor" with the following command:
$ sudo systemctl start apparmor.service
Note: AppArmor must have properly configured profiles for applications and home directories. All configurations will be based on the actual system setup and organization and normally are on a per role basis. Refer to the AppArmor documentation for more information on configuring profiles.
Verify Ubuntu 24.04 LTS AppArmor active with the following commands:
$ systemctl is-active apparmor.service
active
If "active" is not returned, this is a finding.
$ systemctl is-enabled apparmor.service
enabled
If "enabled" is not returned, this is a finding.
V-270660
False
UBTU-24-100510
Verify Ubuntu 24.04 LTS AppArmor active with the following commands:
$ systemctl is-active apparmor.service
active
If "active" is not returned, this is a finding.
$ systemctl is-enabled apparmor.service
enabled
If "enabled" is not returned, this is a finding.
M
5673