HP Pro Mini 260 G9 Desktop PC Maintenance and Service Guide - Page 69

Sure Start Secure Boot Keys Protection: Saves a backup copy of Secure Boot Keys so that they can

Page 69 highlights

Table 6-2 Computer Setup Security (continued) Option Description ● Network Controller Configuration Restore: Select to restore the network controller parameters to the factory state saved in the HP Sure Start Private nonvolatile (flash) memory. This setting is available only on computers with built-in NIC. NOTE: This process can take up to 30 seconds. You need to restore this only when the Network Controller Configuration mismatch warning is set. ● Dynamic Runtime Scanning of Boot Block: Verifies the integrity of the BIOS boot block region several times each hour while the computer is running. Default is enabled. ● Sure Start BIOS Settings Protection: When enabled, HP Sure Start locks all critical BIOS settings and provides enhanced protection for these settings using nonvolatile (flash) memory. Default is off. NOTE: An administrator password must be set to activate this setting. ● Sure Start Secure Boot Keys Protection: Saves a backup copy of Secure Boot Keys so that they can be recovered if someone attempts to alter them in an unauthorized manner. ● Enhanced HP Firmware Runtime Intrusion Prevention and Detection: Enables monitoring of HP system firmware executing out of main memory while the operating system is running. Any anomalies detected in HP system firmware that is active while the operating system is running will result in a Sure Start security event being generated. ● Sure Start Security Event Policy. Controls HP Sure Start behavior upon identifying a critical security event (any modification to HP firmware) while the operating system is running. - Log Event Only: HP Sure Start will log all critical security events in the HP Sure Start audio log within the HP Sure Start nonvolatile (flash) memory. - Log Event and notify user: In addition to logging all critical security events, HP Sure Start will notify the user within the operating system that a critical event has occurred. - Log Event and power off system: In addition to logging all critical security events, HP Sure Start turns of the computer upon detecting a HP Sure Start Security Event. Because of the potential for data loss, HP recommends this setting only in situations where security integrity of the system is a higher priority than the risk of potential data loss. ● Sure Start Security Event Boot Notification: Lets you enable a warning message on the startup screen if there is a Sure Start event (BIOS recovery, Memory intrusion, etc.) Secure Boot Configuration. Lets you be sure that an operating system is legitimate before booting to it, making Windows resistant to malicious modification from preboot to full operating system booting, preventing firmware attacks. UEFI and Windows Secure Boot only allow code signed by preapproved digital certificates to run during the firmware and OS boot process. NOTE: An administrator password must be set to activate this setting. Secure Boot must also be enabled. ● Secure Boot: Default is disabled. ● Secure Boot Key Management: Lets you manage the custom key settings. NOTE: Access to these settings requires Sure Start Secure Boot Keys Protection to be disabled. Import Custom Secure Boot Keys: Default is disabled. Clear Secure Boot keys: Lets you delete any previously loaded custom boot keys. Clearing keys will disable secure boot. Default is disabled. Reset Secure Boot keys to factory defaults: Default is disabled. Enable MS UEFI CA key: Disabling this setting alters the Secure Boot key list to further restrict the allowed software components. Set this option to disable to support Device Guard. Default is enabled. 62 Chapter 6 Computer Setup (F10) Utility

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110

Table 6-2
Computer Setup Security
(continued)
Option
Description
Network Controller Configuration Restore: Select to restore the network controller parameters to the
factory state saved in the HP Sure Start Private nonvolatile (flash) memory. This setting is available
only on computers with built-in NIC.
NOTE:
This process can take up to 30 seconds. You need to restore this only when the Network
Controller Configuration mismatch warning is set.
Dynamic Runtime Scanning of Boot Block: Verifies the integrity of the BIOS boot block region several
times each hour while the computer is running. Default is enabled.
Sure Start BIOS Settings Protection: When enabled, HP Sure Start locks all critical BIOS settings and
provides enhanced protection for these settings using nonvolatile (flash) memory. Default is off.
NOTE:
An administrator password must be set to activate this setting.
Sure Start Secure Boot Keys Protection: Saves a backup copy of Secure Boot Keys so that they can be
recovered if someone attempts to alter them in an unauthorized manner.
Enhanced HP Firmware Runtime Intrusion Prevention and Detection: Enables monitoring of HP
system firmware executing out of main memory while the operating system is running. Any
anomalies detected in HP system firmware that is active while the operating system is running
will result in a Sure Start security event being generated.
Sure Start Security Event Policy. Controls HP Sure Start behavior upon identifying a critical security
event (any modification to HP firmware) while the operating system is running.
Log Event Only: HP Sure Start will log all critical security events in the HP Sure Start audio log
within the HP Sure Start nonvolatile (flash) memory.
Log Event and notify user: In addition to logging all critical security events, HP Sure Start will
notify the user within the operating system that a critical event has occurred.
Log Event and power off system: In addition to logging all critical security events, HP Sure Start
turns of the computer upon detecting a HP Sure Start Security Event. Because of the potential
for data loss, HP recommends this setting only in situations where security integrity of the
system is a higher priority than the risk of potential data loss.
Sure Start Security Event Boot Notification: Lets you enable a warning message on the startup
screen if there is a Sure Start event (BIOS recovery, Memory intrusion, etc.)
Secure Boot Configuration
.
Lets you be sure that an operating system is legitimate before booting to it, making Windows resistant to
malicious modification from preboot to full operating system booting, preventing firmware attacks. UEFI
and Windows Secure Boot only allow code signed by preapproved digital certificates to run during the
firmware and OS boot process.
NOTE:
An administrator password must be set to activate this setting. Secure Boot must also be
enabled.
Secure Boot: Default is disabled.
Secure Boot Key Management: Lets you manage the custom key settings.
NOTE:
Access to these settings requires Sure Start Secure Boot Keys Protection to be disabled.
Import Custom Secure Boot Keys: Default is disabled.
Clear Secure Boot keys: Lets you delete any previously loaded custom boot keys. Clearing keys will
disable secure boot. Default is disabled.
Reset Secure Boot keys to factory defaults: Default is disabled.
Enable MS UEFI CA key: Disabling this setting alters the Secure Boot key list to further restrict the
allowed software components. Set this option to disable to support Device Guard. Default is enabled.
62
Chapter 6
Computer Setup (F10) Utility