Client-side Data Protection
V14.3.1
Verify that authenticated data is cleared from client storage, such as the browser DOM, after the client or session is terminated. The 'Clear-Site-Data' HTTP response header field may be able to help with this but the client-side should also be able to clear up if the server connection is not available when the session is terminated.
Required for Level 1, 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 116, 117, 204, 37, 508
V14.3.2
Verify that the application sets sufficient anti-caching HTTP response header fields (i.e., Cache-Control: no-store) so that sensitive data is not cached in browsers.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 116, 117, 204, 37, 508
V14.3.3
Verify that data stored in browser storage (such as localStorage, sessionStorage, IndexedDB, or cookies) does not contain sensitive data, with the exception of session tokens.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 116, 117, 37, 508
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.