Earlier quoted context omitted.
The BIOS. Specifically, the installation of Microsoft's signing key in UEFI secure boot - which requires the other parts (drivers, specifically) of the UEFI BIOS are signed with Microsoft's key as well. Windows 8 is "theoretically" only bootable when secure boot is turned on.
No - http://blogs.msdn.com/b/b8/archive/2011/09/22/protecting-the... "Microsoft does not mandate or control the settings on PC firmware that control or enable secured boot from any operating system other than Windows. [...] A demonstration of this control is found in the Samsung tablet with Windows 8 Developer Preview that was offered to //BUILD/ participants. In the screenshot below you will notice that we designed…
"... other than Windows," i.e. Windows 8 itself "theoretically" wants Secure Boot turned on.
I've read the link; there's no indication that the Windows 8 Logo Compliance requirements force Windows 8 to work with Secure Boot turned off. And obviously, ARM-based Windows 8 systems will require it to be turned on:
http://arstechnica.com/business/2012/01/microsoft-mandating-...