How would I approach this? Do solutions already exist? I am by no means a security expert.
If you verify the components and construction, then keep the machine in a secure location, that should be good. I know there are some bios-level protections that will not allow a boot if the hardware config changed too.