Replies: 1 comment
-
Changes to ASVS 5.0 Requirements specific to CSP documented within #1406 ASVS 5.0 Requirement for the iFrame |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
"2.3 Security Headers" of MVSP is reproduced below:
2.3 Security Headers
Apply appropriate security headers to reduce the application attack surface and limit post exploitation:
* Set a minimally permissive Content Security Policy
* Limit the ability to iframe sensitive application content where appropriate
The parent of this [MVSP] issue is #1151.
Beta Was this translation helpful? Give feedback.
All reactions