1 min read

HTTP Security Headers: Complete Guide

Learn what HTTP security headers do and how headers such as CSP, HSTS, X-Content-Type-Options, and frame protections improve browser security.

HTTP Security Headers: Complete Guide

What Are HTTP Security Headers?

HTTP security headers are response headers that provide instructions to browsers about how a website should be handled. They can reduce exposure to several browser-based security risks.

Important Security Headers

Content-Security-Policy

CSP can restrict the origins and types of resources a browser is allowed to load. A carefully designed policy can reduce the impact of certain cross-site scripting attacks.

Strict-Transport-Security

HSTS tells compatible browsers to use HTTPS for future requests to the site for a defined period.

X-Content-Type-Options

The nosniff value helps prevent browsers from MIME-sniffing responses in situations where doing so could create security problems.

Frame Protections

Frame-related protections can help prevent clickjacking by controlling whether pages can be embedded in frames.

Security Headers Are Not a Complete Security Program

Headers are one layer of defense. They do not replace secure authentication, authorization, input validation, dependency updates, access controls, secure coding, or vulnerability testing.

Our website security audit guide covers additional areas to review.

Conclusion

Review security headers as part of a broader website security audit, especially after server migrations, framework upgrades, and changes to third-party resources.

Tags:
security headersHTTP security headersCSPHSTSwebsite securitysecurity audit