60.6.3.4.3 Physical Restrictions for JTAG Debug Mode
Invasive and non-invasive debug modes are controlled by four input pins of the Debug Access Port: DBGEN, SPIDEN, NIDEN and SPNIDEN.
To restrict the debug to non-secure software parts only, SECDBG must be configured in the customer OTP area.
Programming SECDBG prevents JTAG secure debug irreversibly, but does not lock non-secure debug.