Master boolean index:

Global
secure_mode (Default: false)

disallow programs, such as newrole, from transitioning to administrative user domains.

Module: kernel

Layer: kernel

secure_mode_insmod (Default: false)

disallow programs and users from transitioning to insmod domain.

Module: selinux

Layer: kernel

secure_mode_policyload (Default: false)

prevent all confined domains from loading policy, setting enforcing mode, and changing boolean values. Set this to true and you have to reboot to set it back