How to enable bios secure boot?

I want enable secure boot in BIOS, I just konw we should set SECURE_BOOT_ENABLE as TRUE in DeveloperBox.dsc, But i dont konw that how to build fip_all_arm_tf_mm.bin, And what should i do when build ATF?