Skip to content
arrow_back
search
ISM-1424 policy ASD Information Security Manual (ISM)

Ensure Web Security Through Response Headers

Web servers use security headers to protect web applications from attacks.

record_voice_over

Plain language

Web security response headers are like safety instructions your web server gives out to help protect your website from attacks. If these instructions aren't given, your website might be more vulnerable to hackers who could steal data or damage your online presence.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame-Options are specified by web server software via security policy in response headers.
policy ASD Information Security Manual (ISM) ISM-1424
priority_high

Why it matters

If CSP, HSTS and X-Frame-Options headers are missing, users are more exposed to XSS, clickjacking and HTTPS downgrade/MITM attacks.

settings

Operational notes

Audit response headers (CSP, HSTS, X-Frame-Options) in CI/CD and via scanning; alert on header absence or unexpected changes after deployments.

Mapping detail

Mapping

Direction

Controls