Hardware security recommendations and best practices
When looking at the security of hardware, it's important to keep these considerations in mind:
- Only purchase hardware that has been through a proper hardware certification program. The Windows Hardware Compatibility Program certification process is a great resource to help ensure the hardware is reliable and compatible with Windows.
- Keep your hardware up to date. Just as with software, hardware continues to evolve to become more secure.
- Have an effective and secure system for upgrading firmware/BIOS and ensure the proper protections are enabled to ensure only approved sources can update them.
- Purchase physical hardware that supports BitLocker (TPM 2.0), DRTM, SMM, Secure Boot, DMA Protection, Memory Encryption (AMD/Intel), and hardware-based isolation of application code in memory (TEE with Intel SGX). This will allow you to enable software features that support hardware-based security.
- Turn on VBS as...