External Resource Integrity
V3.6.1
Verify that client-side assets, such as JavaScript libraries, CSS, or web fonts, are only hosted externally (e.g., on a Content Delivery Network) if the resource is static and versioned and Subresource Integrity (SRI) is used to validate the integrity of the asset. If this is not possible, there should be a documented security decision to justify this for each resource.
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 104, 152, 160, 184, 19, 207, 233, 242, 267, 444, 446, 475, 63
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.