BIOS Protection Guidelines - Recommendations of the National Institute of Standards and Technology

BIOS PROTECTION GUIDELINES
the configuration of the BIOS against the organization’s defined policy after BIOS rollback or
reinstallation.
Disposition Phase: Before the computer system is disposed and leaves the organization, the organization
should remove or destroy any sensitive data from the system BIOS. The configuration baseline should be
reset to the manufacturer’s default profile; in particular, sensitive settings such as passwords should be
deleted from the system and keys should also be removed from the key store. If the system BIOS
includes any organization-specific customizations then a vendor-provided BIOS image should be
installed. This phase of the platform life cycle reduces chances for accidental data leakage.
3-5