I'd argue that it only helps check a tick box on corporate security manifest, as it indicates the kernel being booted, is not tampered with.