Maintenance and Service Guide

Table Of Contents
Table 6-2 Computer Setup—Security (continued)
Option Description
Intel SGX is a set of processor code instructions from that allows user-level code to allocate private
regions of memory, that unlike normal process memory is also protected from processes running at
higher privilege levels.
Software control
Disable
Enable
Trusted Execution Technology (TXT)
Intel Trusted Execution Technology is a set of hardware extensions to Intel processors and chipsets that
enhance the digital oice platform with security capabilities such as measured launch and protected
execution. Intel Trusted Execution Technology provides hardware-based mechanisms that help protect
against software-based attacks and protects the condentiality and integrity of data stored or created on
the client PC.
Utilities Hard Drive Utilities
Save/Restore GPT of System Hard Drive
Enabling this feature saves the GUID Partition Table (GPT) of the system hard drive. If the GPT is
subsequently changed, the user is prompted to choose whether to restore GPT.
DriveLock/Automatic DriveLock
Allows you to assign or modify a master or user password for hard drives. When this feature is
enabled, the user is prompted to provide one of the DriveLock passwords during POST. If neither is
successfully entered, the hard drive remains inaccessible until one of the passwords is successfully
provided during a subsequent cold-boot sequence.
NOTE: This selection appears only when at least one drive that supports the DriveLock feature is
attached to the system.
IMPORTANT: Be aware that these settings take place immediately. It is not necessary to save.
IMPORTANT: Be sure to document the DriveLock password. Losing a DriveLock password will
render a drive permanently locked.
After you select a drive, the following options are available:
- Set DriveLock Master Password. Sets the drives master password but does not enable DriveLock.
- Enable DriveLock. Sets the drive’s user password and enables DriveLock.
Secure Erase
Lets you select a hard drive to completely erase.
After you erase a hard drive with a program that uses Secure Erase rmware
commands, no le
recovery program, partition recovery program, or other data recovery method can extract data from
the drive.
Allow OPAL Hard Drive SED Authentication
Default is disabled.
System Management
Command
Allows authorized personnel to reset security settings during a service event. Default is enabled.
Restore Security Settings
to Default
This action resets security devices, clears BIOS passwords (not including DriveLock), and restores settings
in the Security menu to factory defaults.
Computer Setup—Security 77