A system for simplifying selection of security profile rules within a
computer system utilizes a display device and a security application. The
security application defines a list of security rules for locking down
resources of a computer system and categorizes these rules into a
plurality of categories. The security application displays at least one
of these categories on a screen of the display device. When a user
selects one of the categories, the security application determines which
of the security rules are associated with the selected category and
displays each of these associated security rules. The user then may
enable ones of the displayed rule, and the security application, in
response to an activation request, causes the computer system to enforce
the enabled rules by modifying a machine state of the computer system.