Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

HP SURE START

INFOSHEET

HP Sure Start1 is an advanced hardware-enforced solution


providing comprehensive firmware and firmware setting security.
Starting as the world’s first self-healing BIOS, HP Sure Start now
extends beyond the BIOS to protect critical firmware that
antivirus solutions can’t protect. Providing hardware enforced
self-healing protection of boot-critical firmware from malware,
rootkits, or corruption to help you maintain business continuity in
the face of destructive attacks to the firmware.
FIRMWARE ATTACKS INDUSTRY’S FIRST integration with any management console,
ARE A CURRENT SELF-HEALING BIOS including modern management consoles.

THREAT
Starting as the world’s first hardware- UNIQUE FIRMWARE
Mosaic Regressor, like Lojax and other enforced self-healing BIOS protection, PROTECTION
forms of BIOS attacks, have evolved to new and after generations of enhancements,
categories of threats impacting PCs. These today’s HP Sure Start provides the most HP Sure Start provides a unique, and robust
attacks have become difficult to detect, are comprehensive PC firmware protection and set of protection capabilities.
persistent, and are hard to remove. They are resilience solution available on the market.
• Protection both before firmware is executed
powerful, gaining total control of a PC with and at runtime
In the event of a malware attack on the
the highest level of privilege.
BIOS or Critical Firmware, HP Sure Start • Protects CODE and DATA
If malware affects the BIOS or critical automatically detects the change, notifies
firmware, the attacker can steal valuable the user, securely logs the event for IT and • Intel Manageability Engine firmware / AMD
restores the most recent good version of the Secure Processor / CPU microcode
data, insert ransomware, or render your PC
inoperable. BIOS or firmware.
• Cryptographically protected storage of
settings and secrets
Hardware-enforced protection of and HP Sure Start works by identifying any
resilience for both BIOS and other critical unauthorized changes to the BIOS or critical • Dedicated/isolated policy and recovery
firmware at bootup and during operation is firmware, rather than trying to find known firmware storage
more important than ever. malware—which means that HP Sure Start
can protect you against attacks the world has • Active even when PC is off. Operates
independently of main CPU
HARDWARE-ENFORCED never seen before.

PROTECTION • Closed and Open Chassis Direct Memory


MANAGEABILITY Access attack protection
Since 2014, HP Sure Start has been enabled
by a unique hardware element—the HP
HP Sure Start gives you automated protection PRODUCT PORTFOLIO
that can be managed centrally by your IT
Endpoint Security Controller. SUPPORT
team. You can set HP Sure Start settings
HP Sure Start leverages the HP Endpoint remotely and monitor tamper alerts with the HP Sure Start is included from the factory
Security Controller for strong, hardware- following manageability solutions. across a wide range of the HP commercial
based protection of the code, data, and product portfolio.
• Microsoft® System Center Configuration
secrets stored by the BIOS and critical Manager through the HP Manageability
firmware. • ZBook & Z Workstations
Integration Kit2 (HP MIK) plug-in.
• Pro & Elite Notebooks and Desktops (Intel
• HP Client Management Script Library is a
vPro & non-vPro and AMD processors)
powerful tool that enables straightforward

HP SURE START • Select RPOS and Thin Clients


HP WOLF SECURITY

CERTIFICATES & FREQUENTLY ASKED


STANDARDS QUESTIONS
Q: What do I need to do to benefit from Q: What is a Direct Memory Access (DMA)
HP Sure Start? attacks?
A: HP Sure Start is enabled by default for A: A DMA attack is one where an attacker
CERTIFIED HARDWARE all applicable platforms shipped from the uses peripheral hardware to bypass all
HP factory. There is no need to enable or existing OS memory access controls
The HP Endpoint Security Controller otherwise “deploy” the feature. If your to read or write the OS main memory
used in HP Sure Start platforms device ships with HP Sure Start, you are directly. Systems with HP Sure Start use
protected from the very first time you virtualization hardware to block malicious
has been verified by an accredited
start it. DMA.
independent test lab to operate as
Q: My company uses a custom software Q: What kind of attacks does HP Sure
claimed by HP per publicly available image. Does reimaging the machine Start protect against?
criteria, methodology and processes. delete HP Sure Start? A: HP Sure Start protects against any
unauthorized changes to the BIOS &
A: HP Sure Start is hardware enforced and
critical firmware code or BIOS settings,
exists in the BIOS. Reimaging a machine
both for the boot time code and the
NIST GUIDELINES does not delete it or disable its monitoring
runtime code. These capabilities protect
and self-healing protection of your BIOS
you from a variety of different attacks,
HP Sure Start platforms go and critical firmware.
including new firmware attacks that may
significantly beyond the NIST Certain OS-dependent features of HP Sure surface in the future.
Start (such as remote runtime monitoring
Platform Firm ware Resiliency Q: If malware can attack the BIOS, why
or in-OS notifications in Windows® Event
Guidelines for host processor boot Viewer) can be changed or disabled can’t it corrupt HP Sure Start ’s copy of
firmware, to protect many other boot depending on the OS used. the BIOS?
A: HP uses unique technology, backed by
critical firmware. Q: I have a growing business but no IT the HP Endpoint Security Controller, to
department. Can I still use HP Sure Start? isolate the HP Sure Start clean copy of the
(Special Publication 800-193). A: Yes. Because HP Sure Start is enabled BIOS & critical firmware from the copy of
Learn more in the by default, you are automatically the BIOS & critical firmware that are in use
protected. No IT action is required.
HP Sure Start Whitepaper. by the machine. It is hardware protected
and inaccessible to hackers.

HP SURE START
HP WOLF SECURITY

HP Sure Start Gen6 is available on select HP PCs and requires Windows 10.
1

HP Manageability Integration Kit can be downloaded from http://www.hp.com/go/clientmanagement.


2

Learn more at hp.com/go/computer security.

© Copyright 2021 HP Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for
HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be
construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. Windows is
either a registered trademark or trademark of Microsoft Corporation in the United States and/or other countries. Intel is a trademark or registered
trademark of Intel Corporation or its subsidiaries in the U.S. and/or other countries. AMD is a trademark of Advanced Micro Devices, Inc.

4AA7-2562ENW, May 2021

You might also like