Modern hardware supports "UEFI Secure Boot". I recommend for security reasons the usage of "UEFI Secure Boot". For more information about "UEFI Secure Boot":
https://forums.suse.com/showthread.p...9193#post59193

Be aware that "UEFI Secure Boot" doesn't (yet) support Hibernation/hibernate. See comment 29:
https://bugzilla.redhat.com/show_bug.cgi?id=1467045#c29