Security: Cryptographically signed firmware
Data at Rest Encryption (SEDs with local or external key mgmt)
Secure Boot
Secure Erase
Secured-core server
Secured Component Verification (Hardware integrity check)
Silicon Root of Trust
System Lockdown (requires iDRAC9 Enterprise or Datacenter)
TPM 2.0 FIPS, CC-TCG certified, TPM 2.0 China NationZ
Security: UEFI Secure Boot and Secure Start support
Tamper-free updates - components digitally signed and verified
Immutable Silicon Root of Trust
Ability to rollback firmware
FIPS 140-2 validation
Secure erase of NAND/User data
Common Criteria certification
TPM (Trusted Platform Module) 1.2 option
Configurable for PCI DSS compliance
TPM (Trusted Platform Module) 2.0 option
Advanced Encryption Standard (AES) and Triple Data Encryption Standard (3DES) on browser
Bezel Locking Kit option
Support for Commercial National Security Algorithms (CNSA)
Chassis Intrusion detection option
Secure Recovery - recover critical firmware to known good state on detection of compromised firmware