Use the portable rom builder romnibus.pl for Windows as well as Linux hosts.
PlatSecEnforcement ON
PlatSecDiagnostics ON
PlatSecDisabledCaps -TCB+CommDD-PowerMgmt+MultimediaDD-ReadDeviceData+WriteDeviceData-DRM+TrustedUI-ProtServ+DiskAdmin-NetworkControl+AllFiles-SwEvent+NetworkServices-LocalServices+ReadUserData-WriteUserData+Location