A product of the National Security Agency, and well supported by the security community,
SELinux implements a mandatory access control architecture for the Linux kernel and major subsystems that keeps every process in check, ensuring that the action of one process cannot flow into another. Even the superuser is placed in isolation.