Removed EPOCROOT option as it's not necessary to pass it in this way - the FLM gets it from the environment anyway.
PlatSecEnforcement ON
PlatSecDiagnostics ON
PlatSecDisabledCaps -TCB+CommDD-PowerMgmt+MultimediaDD-ReadDeviceData+WriteDeviceData-DRM+TrustedUI-ProtServ+DiskAdmin-NetworkControl+AllFiles-SwEvent+NetworkServices-LocalServices+ReadUserData-WriteUserData+Location