30 Pre-operating system managementapplicationsNOTE: If your operating system begins to load before you press F2, wait for the system to finish booting, and then restartyoursystemandtryagain.3 Onthe System Setup Main Menu screen, click System BIOS.4 On the System BIOS screen, click System Security.Related linksSystem SecuritySystem Security Settings detailsSystem Security Settings detailsThe System Security Settings screen details are explained as follows:Option DescriptionIntel AES-NI ImprovesthespeedofapplicationsbyperformingencryptionanddecryptionbyusingtheAdvancedEncryptionStandard Instruction Set (AES-NI). This option isset to Enabledbydefault.System Password Sets the system password. This option is set to Enabled bydefault and is read-only if the password jumper is notinstalled in thesystem.Setup Password Sets the setup password. This option is read-onlyif the password jumper is not installed inthe system.Password Status Locks the system password. This option is set to Unlockedbydefault.TPM Security NOTE: The TPM menu is available only when the TPM module is installed.Enables you to control the reporting mode of the TPM. The TPM Security option is set to Off by default. You canonly modify the TPM Status, TPM Activation, and Intel TXT fields if the TPM Status field is set to either On withPre-boot Measurements or On without Pre-boot Measurements.TPMInformation Changes the operational state of the TPM. This option is set to No Change by default.TPM Status SpecifiestheTPMstatus.TPM Command CAUTION: Clearing the TPM results inthelossofall keys inthe TPM. Thelossof TPMkeys mayaffectbooting to the operating system.Clears all the contents of the TPM. The TPM Clear option is set to No by default.Intel TXT Enables or disables the Intel Trusted ExecutionTechnology (TXT) option.Toenable the IntelTXToption,virtualization technology and TPM Securitymust be enabled with Pre-boot measurements. This option is set toOffby default.Power Button Enables or disables the power button on the front of the system. This option is set to Enabled by default.AC PowerRecoveryUEFI VariableAccessSets how the system behaves after AC power is restored to the system. This option is set to Last by default.Provides varying degrees of securing UEFI variables. Whenset to Standard (the default), UEFI variables areaccessible in the operating system per the UEFI specification. When set to Controlled, selected UEFI variables areprotected in the environment and new UEFI boot entries are forced to be at the end of the current boot order.Secure Boot Enables SecureBoot, wherethe BIOSauthenticateseachpre-boot image byusing thecertificatesinthe SecureBoot Policy. Secure Bootisdisabledbydefault.Secure Boot Policy When Secure Boot policy is set to Standard, the BIOS uses the system manufacturer’s key and certificates toauthenticate pre-boot images. When SecureBootpolicyissetto Custom, the BIOS usestheuser-definedkey andcertificates. Secure Boot policy is set to Standardbydefault.SecureBoot PolicySummarySpecifies the list of certificates and hashes that secure boot uses to authenticate images.