Page 580 - (ISC)² CISSP Certified Information Systems Security Professional Official Study Guide
P. 580
facilitate version updates. The process of updating the BIOS is known
as “flashing the BIOS.”
There have been a few examples of malicious code embedding itself
into BIOS/firmware. There is also an attack known as phlashing, in
which a malicious variation of official BIOS or firmware is installed
that introduces remote control or other malicious features into a
device.
Since 2011, most system manufacturers have replaced the traditional
BIOS system on their motherboards with Unified Extensible Firmware
Interface (UEFI). UEFI is a more advanced interface between
hardware and the operating system, which maintains support for
legacy BIOS services.
Device Firmware
Many hardware devices, such as printers and modems, also need some
limited processing power to complete their tasks while minimizing the
burden placed on the operating system itself. In many cases, these
“mini” operating systems are entirely contained in firmware chips
onboard the devices they serve. As with a computer’s BIOS, device
firmware is frequently stored on an EEPROM device so it can be
updated as necessary.

