https://github.com/lfit/itpol/blob/master/linux-workstation-security.md
Для Ъ немного выдержек:
- System supports SecureBoot (CRITICAL)
- UEFI boot mode is used (not legacy BIOS) (CRITICAL)
- SecureBoot is enabled (CRITICAL)
- Distro choice: Fully supports UEFI and SecureBoot (CRITICAL)
- Firefox for work and high security sites; NoScript (CRITICAL)
- Use a password manager (CRITICAL)
Дискасс, в общем. Особенно интересно мнение любителей legacy и биоса. Ну и нелюбителей SecureBoot.