ASSERT_RETURN_ERROR (PcdStatus);\r
\r
DEBUG ((DEBUG_INFO, "SEV is enabled (mask 0x%lx)\n", EncryptionMask));\r
+\r
+ //\r
+ // Set Pcd to Deny the execution of option ROM when security\r
+ // violation.\r
+ //\r
+ PcdStatus = PcdSet32S (PcdOptionRomImageVerificationPolicy, 0x4);\r
+ ASSERT_RETURN_ERROR (PcdStatus);\r
}\r