What are the recommended BIOS settings to secure a ThinkPad X230?
I've searched online and on the forums but I don't see a guide and the documentation I've read on the BIOS settings are cryptic.
My X230 has the latest BIOS. I'm running Windows 8.1 x64 with Bitlocker. What settings should I enable/disable, etc. to make the system as secure as possible?
Thanks!
X230 BIOS Security Recommended Settings
-
rkawakami
- Admin

- Posts: 10052
- Joined: Sun Jun 04, 2006 1:26 am
- Location: San Jose, CA 95120 USA
- Contact:
Re: X230 BIOS Security Recommended Settings
Welcome to thinkpads.com!
Thinkpad BIOS security comes in three basic flavors:
- Power-on password; prompts you each time the system is powered up. This is the least secure roadblock as it's easily removed (just read the description in the Hardware Maintenance Manual).
- BIOS (aka Supervisor) password; prompts you each time you attempt to access the BIOS. This can result in the common "bricking system" situation. If you have set both the power-on and BIOS password, removing the power-on password will automatically lock the system so that you will need to provide the BIOS password upon the next boot. If you don't know the BIOS password, the system will not boot anything. As with most computer security systems, this one can be circumvented but it requires some effort. Password is stored on the motherboard and the factory-recommended fix is to replace the motherboard.
- Hard drive password; prompts you each time the system is accessed from a boot or exit-from-hibernation event. This is the most secure system for protecting your data as it requires the correct password before the system even gets to the Windows login. Password goes with the drive so moving it to another system does not good.
As with any password-based system, your security is only as good as the strength of your selected passwords. DO NOT use the same password for all three locks. If your goal is to make it as hard as possible for somebody to steal/access the data on your drive, then I'd set all three. It can be a hassle if you are constantly booting the system but it's the most secure. Note that in "normal" operation (simply powering up or booting), if all three passwords are set, then you only need to enter two: power-on and HD password. The BIOS password will not be required and in fact, you won't even know it's been set as long as you don't try accessing the BIOS menu.
Thinkpad BIOS security comes in three basic flavors:
- Power-on password; prompts you each time the system is powered up. This is the least secure roadblock as it's easily removed (just read the description in the Hardware Maintenance Manual).
- BIOS (aka Supervisor) password; prompts you each time you attempt to access the BIOS. This can result in the common "bricking system" situation. If you have set both the power-on and BIOS password, removing the power-on password will automatically lock the system so that you will need to provide the BIOS password upon the next boot. If you don't know the BIOS password, the system will not boot anything. As with most computer security systems, this one can be circumvented but it requires some effort. Password is stored on the motherboard and the factory-recommended fix is to replace the motherboard.
- Hard drive password; prompts you each time the system is accessed from a boot or exit-from-hibernation event. This is the most secure system for protecting your data as it requires the correct password before the system even gets to the Windows login. Password goes with the drive so moving it to another system does not good.
As with any password-based system, your security is only as good as the strength of your selected passwords. DO NOT use the same password for all three locks. If your goal is to make it as hard as possible for somebody to steal/access the data on your drive, then I'd set all three. It can be a hassle if you are constantly booting the system but it's the most secure. Note that in "normal" operation (simply powering up or booting), if all three passwords are set, then you only need to enter two: power-on and HD password. The BIOS password will not be required and in fact, you won't even know it's been set as long as you don't try accessing the BIOS menu.
Ray Kawakami
X22 X24 X31 X41 X41T X60 X60s X61 X61s X200 X200s X300 X301 Z60m Z61t Z61p 560 560Z 600 600E 600X T21 T22 T23 T41 T60p T410 T420 T520 W500 W520 R50 A21p A22p A31 A31p
NOTE: All links to PC-Doctor software hosted by me are dead. Files removed 8/28/12 by manufacturer's demand.
X22 X24 X31 X41 X41T X60 X60s X61 X61s X200 X200s X300 X301 Z60m Z61t Z61p 560 560Z 600 600E 600X T21 T22 T23 T41 T60p T410 T420 T520 W500 W520 R50 A21p A22p A31 A31p
NOTE: All links to PC-Doctor software hosted by me are dead. Files removed 8/28/12 by manufacturer's demand.
-
- Similar Topics
- Replies
- Views
- Last post
-
-
1440 x 900 Or 1600 x 900 Displays Compatible For X230 (And Future Plans With X230)
by TheMagicT410 » Sat Feb 18, 2017 10:02 pm » in ThinkPad X230 and later Series - 4 Replies
- 1002 Views
-
Last post by TheMagicT410
Sun Feb 19, 2017 8:45 am
-
-
-
X230 Users...my X230 doesn't like my 16gb G.Skill memory kit
by mr.rhtuner » Sat Mar 18, 2017 8:00 pm » in ThinkPad X230 and later Series - 14 Replies
- 1173 Views
-
Last post by Frenel
Sun May 21, 2017 12:28 pm
-
-
-
FS: X230 US keyboard (backlit) - $25, X230 screen panel - free
by systema » Mon May 08, 2017 8:57 am » in Marketplace - Forum Members only - 0 Replies
- 254 Views
-
Last post by systema
Mon May 08, 2017 8:57 am
-
-
-
Z60m - Recommended Windows version and some other stuff.
by larsoverland » Wed Jan 18, 2017 9:47 am » in ThinkPad R, A, G and Z Series - 3 Replies
- 1427 Views
-
Last post by larsoverland
Thu Jan 19, 2017 11:22 pm
-
Who is online
Users browsing this forum: No registered users and 4 guests



