HTTP Strict Transport Security (HSTS)
Site upgrades to a secure connection.
(How ScanGov measures tasklist priorities.)
HTTP Strict Transport Security is a security feature that:
Key points:
Strict-Transport-Security
).As a site visitor, I want the website to automatically redirect to HTTPS and prevent any connection via HTTP so that my data is always encrypted and secure during transmission.
Example header:
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
(ScanGov messaging when a site fails a standard)
Site doesn't force secure connection; easier for hackers to intercept.