Web Frontend Security Documentation
V3.1.1
Verify that application documentation states the expected security features that browsers using the application must support (such as HTTPS, HTTP Strict Transport Security (HSTS), Content Security Policy (CSP), and other relevant HTTP security mechanisms). It must also define how the application must behave when some of these features are not available (such as warning the user or blocking access).
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 104, 152, 19, 202, 207, 21, 22, 220, 233, 242, 466, 518, 554, 593, 63, 87, 89
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.