And I stated >>it was possible to run Win PE 5. regardless of UEFI. There seems to be a contradiction or I am not reading it correctly.
you stated it was possible to run winpe 5.0 regardless without setting boot order. but the way uefi works is it will always boot the first os it finds, so if the boot order isn't set to boot your restore media first, either with the quick F12 1 time boot option or actually going into uefi and permanently changing the boot order there then there is no guarantee it will run.
ie. you have a working but malware infected os running on your hard drive and have previously created a clean image along with a bootable usb winpe 5.0 stick to start the recovery process.
so you insert the stick, start your pc up, expecting the recovery process to start but instead it boots to the infected os your wanting to replace, this is because the boot order is cd/dvd then hard drives then usb sticks, so the uefi first checked for any cd/dvd's and found nothing then checked hard drives and found an os to install so never checked anything else and just installed the infected os.
In any case do you still have to set the boot order so that cd/dvd is first?
so yes you always have to check/set the first boot device so your sure it will boot the correct media your wanting to boot and not any thing else that's bootable it may find first.
like i said earlier manufacturers usually set the boot order so uefi checks cd/dvd, then hard drives, then removable media, then network connection. so unless you've changed things (some people make the hard drives first boot just to get to the desktop slightly quicker.) and always use a cd/dvd recovery medium then you never have to worry or change anything.
Lastly, Does it make sense to look for Legacy if it exists and enable it so you can then use the Macrium cd?
this macrium cd, is it the winpe 5.0 recovery cd/dvd you made? if so then no you never have to worry about secure boot or legacy boot options, in fact for better security it should always be set to uefi and have secure boot enabled.
now you've confused me with the next part,
If there is no legacy, one would then disable secure boot under boot then enable csm under privacy or is enabling csm not necessary after disabling Secure boot.
each uefi bios is slightly different depending on manufacturer so a setting in one type may not be in another type or named differently.
for example in some uefi's just disabling secure boot is enough to boot any program, digitally signed or not yet in others you also have to make sure to enable legacy boot. so in some 1 change will make things boot but in others 2 changes are needed to the settings before it will boot correctly.
so don't really know if for you just disabling secure boot is enough or if you also have to enable csm too.
what exactly does csm stand for anyway? never seen such a setting myself in uefi. 
anyway the software your trying to boot whatever it is always needs to be digitally signed before it will boot with secure boot enabled.
most reputable software will have this digital signature now or in the near future with their latest program versions but there is always some older software that is very useful but will never be digitally signed for one reason or another.
this secure boot thing is a pet peeve of mine because the hardware is yours and you should always be able to install whatever you want to it, but with microsofts licensing agreements especially now with win 10 as far as i know, the secure boot always has to be enabled but also you may now not have the option any more to actually turn it off and boot legacy software which is not signed.
hope that answers your questions or most anyway, keep asking away with anything your still not sure about and we'll see if we can clear things up for you.

ok found it. csm = Compatibility Support Module. or a posh way of saying legacy mode.
should also add, even tho it is a completely different topic but related slightly to this one about uefi and legacy boot options, the partition table of the hard drive makes a big difference on which you need to use.
there are 2 types mbr or gpt, with the hard drive formatted using gpt you need to use uefi because legacy or csm mode will not boot a windows os installed on a gpt partition..