[…]Now, before you even start with your operating system installation, there are a few things you should consider to ensure your pre-boot environment is up to snuff. You will want to make sure:
* UEFI boot mode is used (not legacy BIOS) (ESSENTIAL)
* A password is required to enter UEFI configuration (ESSENTIAL)
* SecureBoot is enabled (ESSENTIAL)
* A UEFI-level password is required to boot the system (NICE-to-HAVE)
https://www.linux.com/news/linux-workstation-security/2017/3/4-security-steps-take-you-install-linux
http://go.linuxfoundation.org/workstation_security_ebook
Sounds interesting, but I don’t see any actual download link for this ebook. I guess I need some sleep.
There is also this: https://firmwaresecurity.com/2015/08/31/linux-foundation-it-security-policies-firmware-guidance/