Skip to content

Secure Boot

What is Secure Boot?

A security standard that ensures a device boots using only software trusted by the manufacturer, preventing rootkits and boot-level malware from loading.

Information Security

Each of these is named in at least one of the same controls as secure boot. The number is how many controls name both.

What the standards actually require on secure boot

Requirements naming secure boot across 6 standards, quoted from the control text.

Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is enabled.

ISM-1745 · Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is ena
MITRE D3FEND1 control

Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load...

MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot · MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot

UR E27 requires equipment manufacturers to deliver hardened CBS with secure default configuration + secure communications. Hardening: minimum services + disabled debug + locked BIOS + secure boot + Trusted Platform Module (TPM) or equivalent root of trust + si...

IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications · IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography

Security Dimension 6 Data Integrity per X.805 Clause 6.6: Data Integrity ensures the correctness or accuracy of data. The data is protected against unauthorized modification + deletion + creation + replication and provides an indication of these unauthorized a...

X805-Dim6-Data-Integrity-Correctness-Accuracy-Unauthorized-Modification-Deletion-Detection · ITU-T X.805 Security Dimension 6 - Data Integrity + Correctness + Accuracy + Unauthorized Modification Prevention + Deletion Detection + Hashing + HMAC + Digital Signatures + Merkle Trees + Blockchain Integrity + File Integrity Monitoring (FIM)

Disclose and operate audit logging + integrity assurance + cybersecurity risk management features per MDS2 AUDT + IGAU + CYBR sections.

MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring · MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring

Questions people ask about secure boot

What is Secure Boot?
A security standard that ensures a device boots using only software trusted by the manufacturer, preventing rootkits and boot-level malware from loading.
Why is Secure Boot important for compliance?
Secure Boot is a key concept in Information Security. Understanding secure boot helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Secure Boot?
Secure Boot appears in the requirement text of Australian Information Security Manual, MITRE D3FEND, IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1), ITU-T X.805 - Security Architecture for End-to-End Communications. Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Secure Boot?
Explore our compliance framework pages to see how secure boot applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Secure Boot applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.