On a personal system you can disable it. Secure boot restricts system boot from random bootable drives, only a signed EFI binary will be booted if enabled. You can however add a custom key and sign all your EFI binaries with it but that's extra work for no gain on a personal system. DC servers on the other hand enforce secure boot without fail.