User's Manual

Table Of Contents
ToprovidereliablesecurityfortheUEFIBIOS,usethesecuritychipandasecurityapplicationwitha
TrustedPlatformModulemanagementfeature.Referto“Settingthesecuritychip”onpage62
.
IfaDiskEncryptionstoragedriveisinstalledinyourcomputer,besuretoprotectthecontentsofyour
computermemoryfromunauthorizedaccessbyuseofdriveencryptionsoftware,suchasMicrosoft
WindowsBitLocker
®
DriveEncryption.See“UsingWindowsBitLockerDriveEncryption”onpage62.
Beforeyoudisposeof,sell,orhandoveryourcomputer,deletedatastoredonit.Formoreinformation,
referto“Noticeondeletingdatafromyoursolid-statedrive”onpage66.
Thesolid-statedrivebuiltintoyourcomputercanbeprotectedbytheUEFIBIOS.
UsingWindowsBitLockerDriveEncryption
Tohelpprotectyourcomputeragainstunauthorizedaccess,usethedriveencryptionsoftware,suchas
WindowsBitLockerDriveEncryption.
WindowsBitLockerDriveEncryptionisanintegralsecurityfeatureofsomeeditionsoftheWindows
operatingsystem.Itcanhelpyouprotecttheoperatingsystemanddatastoredonyourcomputer,even
ifyourcomputerislostorstolen.BitLockerworksbyencryptingalluserandsystemfiles,includingthe
swapandhibernationfiles.
BitLockerusesaTrustedPlatformModuletoprovideenhancedprotectionforyourdataandtoensureearly
bootcomponentintegrity.AcompatibleTPMisdefinedasaV1.2TPM.
TochecktheBitLockerstatus,gotoControlPanel,andclickSystemandSecurityBitLockerDrive
Encryption.
FormoreinformationaboutWindowsBitLockerDriveEncryption,seethehelpinformationsystemofthe
Windowsoperatingsystem,orsearchfor“MicrosoftWindowsBitLockerDriveEncryptionStep-by-Step
Guide”ontheMicrosoftWebsite.
Encryptionsolid-statedrive
SomemodelscontaintheEncryptionsolid-statedrive.Thisfeaturehelpstoprotectyourcomputeragainst
securityattacksonmedia,NANDflash,ordevicecontrollersbyuseofahardwareencryptionchip.Forthe
efficientuseoftheencryptionfeature,setaharddiskpasswordfortheinternalstoragedevice.
Settingthesecuritychip
Strictsecurityrequirementsareimposedonnetworkclientcomputersthattransferconfidentialinformation
electronically.Dependingontheoptionsyouordered,yourcomputermighthaveanembeddedsecuritychip,
acryptographicmicroprocessor.WiththesecuritychipandClientSecuritySolution,youcandothefollowing:
Protectyourdataandsystem
Strengthenaccesscontrols
Securecommunications
Settingthesecuritychip
ThechoicesofferedontheSecurityChipsubmenuundertheSecuritymenuofThinkPadSetupareas
follows:
SecurityChipSelection:SelectDiscreteTPMorIntelPTT.
SecurityChip:Activate,inactivate,ordisablethesecuritychip.
SecurityReportingOptions:Enableordisableeachsecurityreportingoption.
ClearSecurityChip:Cleartheencryptionkey.
62ThinkPadX1CarbonandThinkPadX1YogaUserGuide