We received an audit finding from our internal vulnerability team on Siteminder.
HTTP Security Header Not Detected
Customers are advised to set proper HTTP response headers:
X-Frame-Options (https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options)
X-XSS-Protection (https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-XSS-Protection)
Content Security Policy (https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP)
X-Content-Type-Options (https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options)
Strict-Transport-Security (https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security)
Depending on their server software, customers can set directives in their site configuration or Web.config files.