diff --git a/shared/applicability/runtime_kernel_fips_enabled.yml b/shared/applicability/runtime_kernel_fips_enabled.yml
index d5a58efd3d4..5d1f6f7b55f 100644
--- a/shared/applicability/runtime_kernel_fips_enabled.yml
+++ b/shared/applicability/runtime_kernel_fips_enabled.yml
@@ -1,4 +1,4 @@
 name: cpe:/a:runtime-kernel-fips-enabled
 title: Running kernel has fips mode enabled
 check_id: runtime_kernel_fips_enabled
-bash_conditional: '[ $(sysctl -a | grep -c fips_enabled.*1) -eq 1 ]'
+bash_conditional: "[ \"$(sysctl -a | grep -c 'fips_enabled.*1')\" -eq 1 ]"
diff --git a/shared/applicability/secure_boot.yml b/shared/applicability/secure_boot.yml
index 7d053146539..66f8893c1e4 100644
--- a/shared/applicability/secure_boot.yml
+++ b/shared/applicability/secure_boot.yml
@@ -1,5 +1,5 @@
 name: cpe:/a:secure-boot
 title: System secure boot is enabled
 check_id: secure_boot_enabled
-bash_conditional: "[ $(mokutil --sb-state | awk '{print $NF}') == 'enabled' ]"
+bash_conditional: "[ \"$(mokutil --sb-state | awk '{print $NF}')\" == 'enabled' ]"