Windows 8 System Requirements, page 116:
21. MANDATORY: Enable/Disable Secure Boot. On non-ARM systems, it is required to implement
the ability to disable Secure Boot via firmware setup. A physically present user must be
allowed to disable Secure Boot via firmware setup without possession of PKpriv.
Programmatic disabling of Secure Boot either during Boot Services or after exiting EFI Boot
Services MUST NOT be possible. Disabling Secure MUST NOT be possible on ARM systems.