Security headers and TLS

30 procedures covering CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy. Out of scope here: penetration testing, vulnerability scanning, auth flows.

Security Headers

Certificates

TLS Protocol

Hsts Https

Cookies

Checklists

Questions people ask about this area