Most Linux hardening work stays focused on access. Flip on a control, lock things down, move on. Doesn't mean you're actually covered.

Source: Seccomp, AppArmor, SELinux: Where Linux Security Controls Fall Short