← Back to Baseline

MB-R281

HUMAN VERIFICATION REQUIRED ASVS 3.1.1 Browser-security requirements

MB-C18 ASVS Level 3 Human Assurance Medium

Application documentation states the expected security features that browsers using the application must support (such as HTTPS, HTTP Strict Transport Security (HSTS), Content Security Policy (CSP), and other relevant HTTP security mechanisms). It must also define how the application must behave when some of these features are not available (such as warning the user or blocking access).