CYB-09 · Cyber security
HTTP security headers provide a critical layer of browser-side protection against XSS, clickjacking, MIME sniffing, and data leakage. These headers are visible in any HTTP response and their absence signals a basic security gap to both regulators and attackers.
Trigger
Content-Security-Policy header absent; X-Frame-Options header absent; X-Content-Type-Options: nosniff absent; Referrer-Policy absent
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Add security headers to all web server responses. Use SecurityHeaders.com to test. Start with X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin. Build CSP progressively.
Evidence required
Automated assessment
Verified by the Provantis cyber scanner. Machine checks performed: