Lesson 4.18mIntermediate7.1k students

HTTPS, security headers, and CSP

A handful of response headers remove entire attack classes. CSP is the strongest and the fiddliest, so roll it out in report-only first.

This lesson sits in Hardening and Supply Chain, part of Practical Web Security. It assumes what came before it and leads directly into the next lesson in the module.

In this lesson you will

  • Enforce HTTPS and enable HSTS
  • Set the headers that block framing and sniffing
  • Introduce a content security policy incrementally

Resources