This is set in the hardened linux config as well but sysctl is more flexible & works with any boot.kernelPackages