HP Sure Start
9
Technical white paper | HP Sure Start
Note: Events are persistent in the HP Endpoint Security Controller even after being copied to the Windows Event Viewer.
If the Windows Event Viewer is cleared, the HP Notications Software application will replace all HP Sure Start entries on
the next event that triggers it to check for HP Sure Start event logs.
Types of HP Sure Start Windows Event Viewer events
Event Level Denition
Info Events that are expected to occur during the normal course of operation (e.g., updating the BIOS).
Warning Unexpected events that have occurred but were fully recovered from by HP Sure Start and no user/admin
action is required for the platform to be fully operational. These events are anomalous operations that the
user/admin may want to investigate further, especially if there is a trend of these events across multiple
machines.
Error Events that require the admin/HP service to act on the platforms to fully recover.
HP Sure Start policy controls
Out of the box, the HP system BIOS enables and optimizes HP Sure Start policies for the typical user. Since HP Sure Start
is enabled by default, the typical user is protected by HP Sure Start without having to modify the settings. For advanced
users, the system BIOS provides some control of HP Sure Start behavior, using policy settings in the (F10) BIOS Setup.
Unless otherwise noted, these settings and functions are located under Security/BIOS Sure Start.
Note: Policies are stored within the HP ESC nonvolatile memory that is not directly accessible by the host CPU; therefore,
a reboot is required before any Sure Start settings take eect.
The following HP Sure Start settings and functions are available:
• Verify Boot Block on Every Boot
• BIOS Data Recovery Policy
• Network Controller Conguration Restore (Intel only)
• Prompt on Network Controller Conguration Change (Intel only)
• Dynamic Runtime Scanning of Boot Block (Intel only)
• HP Sure Start BIOS Setting Protection
• HP Sure Start Secure Boot Keys Protection
• Enhanced HP Firmware Runtime Intrusion Prevention and Detection (Intel only)
• HP Firmware Runtime Intrusion Detection (AMD only)
• HP Sure Start Security Event Policy
• HP Sure Start Security Event Boot Notication
• Lock BIOS Version
• Save/Restore MBR of System Hard Drive
• Save/Restore GPT of System Hard Drive
• Boot Sector (MBR/GPT) Recovery Policy