If possible, it's important to maintain an up to date BIOS to both fix BIOS bugs.
In general, for Qubes to work some options must be enabled in the BIOS. These are:
Or the AMD equivalents.
Certain Bios configurations can help improve physical security against some classes of attackers, especially if layered with additional physical protections. See Security/DefenseInDepth.
- Administrator password set, so that it's required to modify BIOS settings
- Change the boot priority to only include the hard drive you're booting from (remove external media)
- Disable any ports that aren't required (firewire, non-used usb ports, etc)