HTTP Strict Transport Security (HSTS)
Site upgrades to a secure connection.
Site upgrades to a secure connection.
(How ScanGov measures tasklist priorities.)
As a site visitor, I want the website to automatically redirect to HTTPS and prevent any connection via HTTP so that my data is always encrypted and secure during transmission.
(ScanGov messaging when a site fails a standard)
Secure connection upgrade not enforced.
All government websites must have HSTS.
Strict Transport Security: Websites and services available over HTTPS must enable HTTP Strict Transport Security (HSTS)12 to instruct compliant browsers to assume HTTPS going forward. This reduces the number of insecure redirects, and protects users against attacks that attempt to downgrade connections to plain HTTP. Once HSTS is in place, domains can be submitted to a “preload list”13 used by all major browsers to ensure the HSTS policy is in effect at all times.
The policy should be deployed at https://domain.gov, not https://www.domain.gov.
HTTP Strict Transport Security is a security feature that:
Key points:
Strict-Transport-Security
).Example header:
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload