OL 9 must enable the fapolicy module.
DISA Rule
SV-271507r1091233_rule
Vulnerability Number
V-271507
Group Title
SRG-OS-000370-GPOS-00155
Rule Version
OL09-00-000341
Severity
CAT II
CCI(s)
- CCI-001774 - Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system.
- CCI-001764 - Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage.
Weight
10
Fix Recommendation
Enable the fapolicyd service with the following command:
$ sudo systemctl enable --now fapolicyd
Check Contents
Verify that OL 9 fapolicyd is active with the following command:
$ systemctl is-active fapolicyd
active
If fapolicyd module is not active, this is a finding.
Vulnerability Number
V-271507
Documentable
False
Rule Version
OL09-00-000341
Severity Override Guidance
Verify that OL 9 fapolicyd is active with the following command:
$ systemctl is-active fapolicyd
active
If fapolicyd module is not active, this is a finding.
Check Content Reference
M
Target Key
5680