I wasn't aware about Intel ME until recently bought a brand new Lenovo ThinkPad and saw the "Intel Management Engine" on BIOS/UEFI boot menu.

The thing is: how can I configure this ME thing in order to avoid (or minimize, at least) possible attacks?

You can't. The whole point of the thing is that it can't be disabled and will always be running to let your theoretical IT department take over your machine.

I got ME disabled in BIOS on my Lenovo S30 (manufactured around 2012 I think). Do you think this option in BIOS setup insufficient to turn it off? Is the ME still running and listening to commands coming from the network?

