HTTP Security Headers: Complete Guide
Learn what HTTP security headers do and how headers such as CSP, HSTS, X-Content-Type-Options, and frame protections improve browser security.
What Are HTTP Security Headers?
HTTP security headers are response headers that provide instructions to browsers about how a website should be handled. They can reduce exposure to several browser-based security risks.
Important Security Headers
Content-Security-Policy
CSP can restrict the origins and types of resources a browser is allowed to load. A carefully designed policy can reduce the impact of certain cross-site scripting attacks.
Strict-Transport-Security
HSTS tells compatible browsers to use HTTPS for future requests to the site for a defined period.
X-Content-Type-Options
The nosniff value helps prevent browsers from MIME-sniffing responses in situations where doing so could create security problems.
Frame Protections
Frame-related protections can help prevent clickjacking by controlling whether pages can be embedded in frames.
Security Headers Are Not a Complete Security Program
Headers are one layer of defense. They do not replace secure authentication, authorization, input validation, dependency updates, access controls, secure coding, or vulnerability testing.
Our website security audit guide covers additional areas to review.
Conclusion
Review security headers as part of a broader website security audit, especially after server migrations, framework upgrades, and changes to third-party resources.