AiVibe

Cybersecurity & Compliance

Content Security Policy (CSP)

A browser security mechanism, delivered as an HTTP response header, that declares which sources of scripts, styles, images, frames and other content a page may load, reducing the impact of cross-site scripting and data injection.

A CSP is a list of directives such as default-src, script-src, style-src, img-src, connect-src and frame-ancestors, each specifying allowed origins or keywords. The browser blocks resources that violate the policy and can send violation reports to a designated endpoint. Strict policies avoid broad allow-lists and instead permit scripts through per-response nonces or hashes, often combined with strict-dynamic, and they block inline event handlers and eval-like functions unless explicitly allowed.

CSP is a defence-in-depth control against XSS: even if an attacker manages to inject markup, a strict policy prevents the injected script from running or sending data to unapproved hosts. The frame-ancestors directive controls which sites may embed the page, protecting against clickjacking and superseding the older X-Frame-Options header. CSP is defined in W3C specifications and supported by all major browsers.

Deploying CSP on an existing site often requires refactoring inline scripts and third-party tags, so teams typically start with the Content-Security-Policy-Report-Only header, review the violations reported and then enforce the policy. Policies that allow unsafe-inline scripts or wildcard sources provide little protection. CSP complements, but does not replace, output encoding and input validation.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Ask AiMuruga can explain Content Security Policy (CSP) for your plant, product or security programme, and draw how it fits.