Saturday, October 3, 2026
GovTech & Cybersecurity Standards Benchmark
Global Digital Verification
✕
Web Security Architecture • 2026 Reference Peer Reviewed

HTTP Security Headers Complete Audit & Hardening Guide (HSTS, CSP, Permissions-Policy)

Comprehensive verification checklist and implementation playbooks for HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy.

WebOTG Security Directorate
16 mins
Oct 03, 2026
1 views
Advertisement

1. Executive Summary & Security Header Architecture

HTTP Security Response Headers provide instructions to client web browsers on how to handle content, enforce TLS encryption, restrict cross-origin framing, and isolate script execution environments. According to the OWASP Secure Headers Project and CERT-In Web Application Security Guidelines, the absence of defensive HTTP headers represents an exploitable security misconfiguration (OWASP A05:2025 / CWE-693) that dramatically amplifies the severity of XSS, Clickjacking, and MIME-confusion vulnerabilities.

Standard Mapping
OWASP A05:2025 • CWE-693 (Protection Mechanism Failure) • GIGW 3.0 Clause 6.1.3 • NIST SP 800-95
Security Header Primary Defense Objective Recommended Baseline Value
Strict-Transport-Security (HSTS) Prevents SSL Stripping and forces HTTPS on all requests max-age=31536000; includeSubDomains; preload
X-Content-Type-Options Prevents MIME-confusion and drive-by download execution nosniff
X-Frame-Options Prevents Clickjacking by disallowing unauthorized framing DENY or SAMEORIGIN
Referrer-Policy Protects sensitive path and query parameters from leaking strict-origin-when-cross-origin
Permissions-Policy Disables unneeded browser APIs (camera, microphone, geolocation) camera=(), microphone=(), geolocation=()
Content-Security-Policy (CSP) Restricts resource loading origins and eliminates inline scripts default-src 'self'; object-src 'none'; frame-ancestors 'self'

2. Auditing Security Headers with cURL & Automated Tools

Auditors should use command-line HTTP inspection to verify that headers are delivered across all status codes (including redirects and error pages).

Method A: Inspecting Headers with cURL

# Fetch only HTTP headers from live target curl -sI https://target-domain.gov # Quick grep audit for essential defense headers curl -sI https://target-domain.gov | grep -iE 'strict-transport-security|content-security-policy|x-content-type-options|x-frame-options|referrer-policy|permissions-policy' # Automated header presence check script for header in "Strict-Transport-Security" "X-Content-Type-Options" "X-Frame-Options" "Referrer-Policy" "Permissions-Policy" "Content-Security-Policy"; do val=$(curl -sI "https://target-domain.gov" | grep -i "^${header}:") if [ -n "$val" ]; then echo -e "[PASS] $val" else echo -e "[FAIL] Missing: $header" fi done

3. Production Server Hardening Recipes

A. Nginx Security Headers Configuration Snippet

Place the following directives inside /etc/nginx/snippets/security-headers.conf. Note the crucial always flag, which ensures headers are added even on 4xx and 5xx error responses:

# Enforce HTTPS strictly for 1 year including all subdomains add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always; # Prevent MIME type sniffing add_header X-Content-Type-Options "nosniff" always; # Defend against UI Redressing (Clickjacking) add_header X-Frame-Options "SAMEORIGIN" always; # Protect URL path disclosures on external navigations add_header Referrer-Policy "strict-origin-when-cross-origin" always; # Restrict sensitive browser device sensors add_header Permissions-Policy "camera=(), microphone=(), geolocation=(self)" always; # Robust Content Security Policy baseline add_header Content-Security-Policy "default-src 'self'; script-src 'self' https://pagead2.googlesyndication.com; style-src 'self' 'unsafe-inline'; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: https:; frame-ancestors 'self'; base-uri 'self'; form-action 'self';" always;

B. Apache (.htaccess or httpd.conf) Recipe

<IfModule mod_headers.c> Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN" Header always set Referrer-Policy "strict-origin-when-cross-origin" Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(self)" Header always set Content-Security-Policy "default-src 'self'; script-src 'self' https://pagead2.googlesyndication.com; style-src 'self' 'unsafe-inline'; font-src 'self' data: https://fonts.gstatic.com; img-src 'self' data: https:; frame-ancestors 'self';" </IfModule>

4. Safe-to-Host Audit Checklist

Header Name Auditor Validation Command Pass Criteria
Strict-Transport-Security curl -sI https://domain.gov | grep -i strict-transport-security Header is present with max-age ≥ 31536000 and includeSubDomains
X-Content-Type-Options curl -sI https://domain.gov | grep -i x-content-type-options Exactly matches nosniff
X-Frame-Options curl -sI https://domain.gov | grep -i x-frame-options Matches DENY or SAMEORIGIN
Referrer-Policy curl -sI https://domain.gov | grep -i referrer-policy Configured to strict-origin-when-cross-origin or no-referrer
Error Response Persistence curl -sI https://domain.gov/non-existent-page-404 Security headers are present on 404/500 responses (verified via always flag)
Advertisement
WE
WebOTG Security Directorate
Application Security Architect

WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.