Lenovo ThinkPad Yoga 15 (English) User Guide - ThinkPad Yoga 15 - Page 90

Flash BIOS Updating

Page 90 highlights

Table 4. Security menu items (continued) Menu item Submenu item Selection Clear Security Chip Enter Physical Presence for Provisioning • Disabled • Enabled Physical Presence for Clear • Disabled • Enabled UEFI BIOS Update Option Flash BIOS Updating by • Disabled End-Users • Enabled Secure RollBack Prevention • Disabled • Enabled Memory Protection Execution Prevention • Disabled • Enabled Comments CMOS Reporting and NVRAM Reporting are always enabled to enhance system security. Note: This item is available when Security Chip is set as Active. This option is used to clear encryption keys. It will not be possible to access already-encrypted data after these keys are cleared. Note: This item is available when Security Chip is set as Active. This option enables or disables the confirmation message when you change the settings of the security chip. This option enables or disables the confirmation message when you clear the security chip. If you select Enabled, all users can update the UEFI BIOS. If you select Disabled, only the person who knows the supervisor password can update the UEFI BIOS. If you select Disabled, you can flash to an earlier version of the UEFI BIOS. If you select Enabled, you cannot flash to an earlier version of the UEFI BIOS. Note: This item is set as Disabled by default when the OS Optimized Defaults on the Restart menu is set as Disabled. This item is set as Enabled by default when the OS Optimized Defaults is set as Enabled. Some computer viruses and worms cause memory buffers to overflow. By selecting Enabled you can protect your computer against attacks by such viruses and worms. If you find that an application program does not run correctly after choosing Enabled, select Disabled and reset the setting. 74 User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174

Table 4. Security menu items (continued)
Menuitem
Submenuitem
Selection
Comments
CMOSReporting
and
NVRAM
Reporting
are always enabled to
enhance system security.
Note:
This item is available when
SecurityChip
is set as
Active
.
Clear Security Chip
Enter
This option is used to clear
encryption keys. It will
not be possible to access
already-encrypted data after
these keys are cleared.
Note:
This item is available when
SecurityChip
is set as
Active
.
Physical Presence for
Provisioning
Disabled
• Enabled
This option enables or disables the
confirmation message when you
change the settings of the security
chip.
Physical Presence for
Clear
• Disabled
Enabled
This option enables or disables the
confirmation message when you
clear the security chip.
Flash BIOS Updating by
End-Users
• Disabled
Enabled
If you select
Enabled
, all users can
update the UEFI BIOS. If you select
Disabled
, only the person who
knows the supervisor password can
update the UEFI BIOS.
UEFIBIOSUpdateOption
Secure RollBack
Prevention
Disabled
• Enabled
If you select
Disabled
, you can flash
to an earlier version of the UEFI
BIOS.
If you select
Enabled
, you cannot
flash to an earlier version of the UEFI
BIOS.
Note:
This item is set as
Disabled
by default when the
OSOptimized
Defaults
on the
Restart
menu is
set as
Disabled
. This item is set
as
Enabled
by default when the
OSOptimizedDefaults
is set as
Enabled
.
MemoryProtection
Execution Prevention
• Disabled
Enabled
Some computer viruses and worms
cause memory buffers to overflow.
By selecting
Enabled
you can
protect your computer against
attacks by such viruses and worms.
If you find that an application
program does not run correctly after
choosing
Enabled
, select
Disabled
and reset the setting.
74
User Guide