RHEL 10 must enable the "fapolicy" module.
DISA Rule
SV-280970r1165265_rule
Vulnerability Number
V-280970
Group Title
SRG-OS-000370-GPOS-00155
Rule Version
RHEL-10-200601
Severity
CAT II
CCI(s)
- CCI-001774 - Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system.
- CCI-001764 - Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage.
Weight
10
Fix Recommendation
Configure RHEL 10 to enable "fapolicyd" with the following command:
$ systemctl enable --now fapolicyd
Check Contents
Verify RHEL 10 "fapolicyd" is active with the following command:
$ systemctl is-active fapolicyd
active
If the "fapolicyd" module is not active, this is a finding.
Vulnerability Number
V-280970
Documentable
False
Rule Version
RHEL-10-200601
Severity Override Guidance
Verify RHEL 10 "fapolicyd" is active with the following command:
$ systemctl is-active fapolicyd
active
If the "fapolicyd" module is not active, this is a finding.
Check Content Reference
M
Target Key
5733