Master boolean index:

Global
secure_mode (Default: false)

disallow programs, such as newrole, from transitioning to administrative user domains.

Module: kernel

Layer: kernel

secure_mode_insmod (Default: false)

Disable kernel module loading.

Module: selinux

Layer: kernel

secure_mode_policyload (Default: false)

Boolean to determine whether the system permits loading policy, setting enforcing mode, and changing boolean values. Set this to true and you have to reboot to set it back.