This is mandating a set of hardware specs which make a machine less susceptible to certain classes of firmware attacks. The hardware already exists now, and I've used machines which would meet this specification to run Linux (with SecureBoot enabled to prevent unauthorised kernel alterations).

