Web Template Frameworks with XSS Protections, v1.0

Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to adopt web template frameworks with built-in cross-site scripting (XSS) protections, across all of its product and service offerings.

Assessment Step

1
Web Template Frameworks with XSS Protections (WebTemplateFrameworkswithXSSProtections)
Across all of its product and service offerings, does the organization adopt web template frameworks with built-in cross-site scripting (XSS) protections?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Web Template Frameworks with XSS Protections
Across all of its product and service offerings, the organization must adopt web template frameworks with built-in cross-site scripting (XSS) protections.
Citation
SBDP
(doc)