We need to test a default setting for package removal, since the current state my be a little bit confusing for hardening implementors. See the following discussions:
Currently, we decided to set the default for package removal to true:
default[:security][:packages][:clean] = true