# Configure security services Qualcomm Linux Security provides a wide range of security configurations aimed at enhancing device security, ensuring software authenticity and integrity, and protecting critical and sensitive information for both developers and users. This section guides you through the following configuration workflows. ![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [Enable secure boot](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-secure-boot.html#enable-secure-boot) ![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [Enable secure boot on SAIL](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-secure-boot-on-sail.html#enable-secure-boot-on-sail) ![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [Enable UEFI secure boot](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-uefi-secure-boot.html#enable-uefi-secure-boot) ![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [Enable device configuration from Qualcomm TEE](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-device-devcfg-from-qtee.html#enable-device-devcfg-from-qtee) ![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [Enable SELinux](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-selinux.html#enable-selinux) ![icol](data:image/png;base64,UklGRpwAAABXRUJQVlA4TJAAAAAvF8AFEH+goG0bxqU4/kwuDQNp22T7Hd2/tito24Zxx5/keDw1kaw6pAoFSMK/iB/qXPECxHNdR35a5LyfAAqFBeA/Hm9S6E2CUWxbbf5gABvsO2yRgABSJERZJERCJMRBb/sM1UBE/xWmbcM46e4lUEfjF2LpUYCVX6HiHS5YDP3Jhgk/hl+K1nlAASYCVQQ=) [Install or upgrade SoftSKU feature packs](https://docs.qualcomm.com/doc/80-70030-11/topic/upgrade-qualcomm-wes-feature-pack.html#upgrade-qualcomm-wes-feature-pack) ## Next steps - To adjust Qualcomm TEE configurations, see [Enable device configuration (Devcfg) from Qualcomm TEE](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-device-devcfg-from-qtee.html#enable-device-devcfg-from-qtee). - To enable secure boot and to ensure only trusted applications runs on the device, see [Enable secure boot](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-secure-boot.html#enable-secure-boot). - To enforce strict access controls, see [Enable SELinux](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-selinux.html#enable-selinux). - To ensure that only the verified and trusted applications are loaded during the startup process, see [Enable UEFI secure boot](https://docs.qualcomm.com/doc/80-70030-11/topic/enable-uefi-secure-boot.html#enable-uefi-secure-boot). - To install or upgrade QCS5430 SoftSKU feature packs, see: [Install or upgrade SoftSKU feature packs](https://docs.qualcomm.com/doc/80-70030-11/topic/upgrade-qualcomm-wes-feature-pack.html#upgrade-qualcomm-wes-feature-pack). Last Published: Jun 25, 2026 [Previous Topic Verify the security configurations of Qualcomm Linux](https://docs.qualcomm.com/bundle/publicresource/80-70030-11/topics/bring-up.md) [Next Topic Enable device configuration (Devcfg) from Qualcomm TEE](https://docs.qualcomm.com/bundle/publicresource/80-70030-11/topics/enable-device-devcfg-from-qtee.md)