64.5.4.2.2 Physical Restrictions for JTAG Debug Mode
Invasive and non-invasive debug modes are controlled by four input pins of the Debug Access Port: DBGEN, SPIDEN, NIDEN and SPNIDEN.
In order to restrict the debug to nonsecure software parts only, the SEC_DEBUG_DIS fuse has to be configured in the customer fuse matrix.
Programming this fuse prevents JTAG secure debug irreversibly, but does not lock non-secure debug.