1. Executive Summary & Security Header Architecture
HTTP Security Response Headers provide instructions to client web browsers on how to handle content, enforce TLS encryption, restrict cross-origin framing, and isolate script execution environments. According to the OWASP Secure Headers Project and CERT-In Web Application Security Guidelines, the absence of defensive HTTP headers represents an exploitable security misconfiguration (OWASP A05:2025 / CWE-693) that dramatically amplifies the severity of XSS, Clickjacking, and MIME-confusion vulnerabilities.
| Security Header | Primary Defense Objective | Recommended Baseline Value |
|---|---|---|
| Strict-Transport-Security (HSTS) | Prevents SSL Stripping and forces HTTPS on all requests | max-age=31536000; includeSubDomains; preload |
| X-Content-Type-Options | Prevents MIME-confusion and drive-by download execution | nosniff |
| X-Frame-Options | Prevents Clickjacking by disallowing unauthorized framing | DENY or SAMEORIGIN |
| Referrer-Policy | Protects sensitive path and query parameters from leaking | strict-origin-when-cross-origin |
| Permissions-Policy | Disables unneeded browser APIs (camera, microphone, geolocation) | camera=(), microphone=(), geolocation=() |
| Content-Security-Policy (CSP) | Restricts resource loading origins and eliminates inline scripts | default-src 'self'; object-src 'none'; frame-ancestors 'self' |
2. Auditing Security Headers with cURL & Automated Tools
Auditors should use command-line HTTP inspection to verify that headers are delivered across all status codes (including redirects and error pages).
Method A: Inspecting Headers with cURL
3. Production Server Hardening Recipes
A. Nginx Security Headers Configuration Snippet
Place the following directives inside /etc/nginx/snippets/security-headers.conf. Note the crucial always flag, which ensures headers are added even on 4xx and 5xx error responses:
B. Apache (.htaccess or httpd.conf) Recipe
4. Safe-to-Host Audit Checklist
| Header Name | Auditor Validation Command | Pass Criteria |
|---|---|---|
| Strict-Transport-Security | curl -sI https://domain.gov | grep -i strict-transport-security |
Header is present with max-age ≥ 31536000 and includeSubDomains |
| X-Content-Type-Options | curl -sI https://domain.gov | grep -i x-content-type-options |
Exactly matches nosniff |
| X-Frame-Options | curl -sI https://domain.gov | grep -i x-frame-options |
Matches DENY or SAMEORIGIN |
| Referrer-Policy | curl -sI https://domain.gov | grep -i referrer-policy |
Configured to strict-origin-when-cross-origin or no-referrer |
| Error Response Persistence | curl -sI https://domain.gov/non-existent-page-404 |
Security headers are present on 404/500 responses (verified via always flag) |
WebOTG Security Directorate
WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.