Internet Information Services (IIS) Securing Best Prac \ Website Headers

ASPNET \ Web Server \ Misconfiguration: Missing Error HandlingDisable Detailed errors in IIS
 Cache-Controlprivate, no-store
Referrer-Policystrict-origin-when-cross-originwe can conclude that the default  setting deals with most of the security
X-XSS-Protection1; mode=block
Strict-Transport-Securitymax-age=31536000; includeSubDomains; preloadHSTS Enable
X-Frame-Options SAMEORIGIN
Content-Security-Policydefault-src ‘self’; connect-src *; font-src *; frame-src *; img-src * data:; media-src *; script-src * ‘unsafe-inline’ ‘unsafe-eval’; style-src * ‘unsafe-inline’;
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)