HSI:3 compliance downgraded to HSI:1

Not sure when or why but my HSI security assessment changed from HSI:3 to HSI:1 recently. According to the report I can view in Gnome the following two features are not enabled anymore.

How could I re-enable them? I haven’t found any straightforward way to do that in the UEFI BIOS.

Framework Laptop 13 (AMD Ryzen 7040Series)
AMD Ryzen 5 7640U w/ Radeon 760M Graphics
BIOS 3.18
Debian GNU/Linux forky/sid (updated today, kernel 7.1.3)

HSI-1 Test all passed

HSI-2 Tests
AMD Platform Secure Boot: ! Fail (Not Enabled)
AMD Firmware Write Protection: Pass (Enabled)
TPM Reconstruction: Pass (Valid)
IOMMU Protection: Pass (Enabled)
Platform Debugging: Pass (Locked)

HSI-3 Tests
UEFI Memory Protection: ! Fail (Not Locked)
Pre-boot DMA Protection: Pass (Enabled)
AMD Firmware Replay Protection: Pass (Enabled)
Suspend To RAM: Pass (Not Enabled)
Control-flow Enforcement Technology: Pass (Supported)
Suspend To Idle: Pass (Enabled)