Security Requirements
To provide any security your system needs to defend against an attacker turning UEFI Secure Boot off or being able to sign binaries with the keys we are going to generate.
The easiest way to achieve this is to:
- Enable a BIOS password in your system.
- Use full disk encryption.
The topic of security around Secure Boot is complex. We are only scratching the surface here and a comprehensive guide is out of scope.