Ensuring that we operate system security
As a part of our defense-in-depth look at securing Windows 11 systems, this section looks at the security measures we can take to protect the OS. These include Secure Boot and Trusted Boot, the Windows Security app, encryption, security baselines, and Defender, which we will discuss in the following sections.
Introducing Secure Boot and Trusted Boot
The initial boot-up protection is carried out by Secure Boot. The firmware is verified that it is digitally signed, and then all code that runs before the OS is checked by Secure Boot.