← Rules Catalog
highsystemsystem-selinux-enforcing

Set SELinux to enforcing mode

SELinux must run in enforcing mode so mandatory access control policy is applied rather than merely logged.

selinuxmacsystem

Frameworks satisfied

DISA STIG
rhel9: RHEL-09-431015 · V-257786 · CAT II
NIST 800-53
AC-3AC-6
CIS Benchmark
1.6.1.2

Platforms

rhel 8+rhel 9+

Check

selinux_stateenforcing

Remediation

selinux_setSELINUX=enforcingpersisted to /etc/selinux/config