Boot Guard is a feature where the CPU verifies the digital signature of the BIOS firmware before it even executes the first line of code.
In the past, if malware infected your BIOS (like the infamous "BIOS Rootkit" theoretically demonstrated by elite hackers), it could survive even if you wiped your hard drive and reinstalled Windows. The virus lived in the motherboard chip. bios file