The ISBC reads the Command Sequence Control (CSC) and the header of the external bootloader. It compares the hash of the public key in the header against the hash stored in the hardware fuses.
Beyond signing (authentication), use the SEC engine to encrypt the bootloader image on the flash to protect your intellectual property. qoriq trust architecture 2.1 user guide
The ISBC (in ROM) initializes the SEC engine. The ISBC reads the Command Sequence Control (CSC)
You can test Secure Boot using "Development" keys without blowing fuses by using the SoC's override registers. qoriq trust architecture 2.1 user guide