<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic recommended policy for Content Security Policy in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/recommended-policy-for-Content-Security-Policy/m-p/2089402#M29701</link>
    <description>&lt;P&gt;a customer of ours wants to setup Content Security Policy (CSP). i have learned that i can add that via Additional Response Headers in Qlik Sense QMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but i could not find any recommended policies for Qlik. does anyone have experience with this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2023 07:32:53 GMT</pubDate>
    <dc:creator>dobak</dc:creator>
    <dc:date>2023-06-30T07:32:53Z</dc:date>
    <item>
      <title>recommended policy for Content Security Policy</title>
      <link>https://community.qlik.com/t5/Management-Governance/recommended-policy-for-Content-Security-Policy/m-p/2089402#M29701</link>
      <description>&lt;P&gt;a customer of ours wants to setup Content Security Policy (CSP). i have learned that i can add that via Additional Response Headers in Qlik Sense QMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but i could not find any recommended policies for Qlik. does anyone have experience with this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 07:32:53 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/recommended-policy-for-Content-Security-Policy/m-p/2089402#M29701</guid>
      <dc:creator>dobak</dc:creator>
      <dc:date>2023-06-30T07:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: recommended policy for Content Security Policy</title>
      <link>https://community.qlik.com/t5/Management-Governance/recommended-policy-for-Content-Security-Policy/m-p/2089614#M29702</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/218817"&gt;@dobak&lt;/a&gt;&amp;nbsp;,&amp;nbsp;In general, Content-Security-Policy is not something that Qlik has recommendations for. This is more of an environment hardening issue.&lt;/P&gt;
&lt;P&gt;As part of best-effort, I can point you to the most relevant articles and discussions about this as there is some good info in there:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/What-is-CSP-Content-Security-Policy-and-How-does-it-Relate-to/ta-p/1710258" target="_blank"&gt;https://community.qlik.com/t5/Official-Support-Articles/What-is-CSP-Content-Security-Policy-and-How-does-it-Relate-to/ta-p/1710258&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-add-additional-response-headers-in-Qlik-Sense/ta-p/1717563" target="_blank"&gt;https://community.qlik.com/t5/Official-Support-Articles/How-to-add-additional-response-headers-in-Qlik-Sense/ta-p/1717563&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Security-Governance/Not-able-to-apply-Content-Security-Policy-on-Qliksense/td-p/1998893" target="_blank"&gt;https://community.qlik.com/t5/Security-Governance/Not-able-to-apply-Content-Security-Policy-on-Qliksense/td-p/1998893&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/How-to-determine-string-policy-for-Content-Security-Policy/ta-p/1715491" target="_blank"&gt;https://community.qlik.com/t5/Official-Support-Articles/How-to-determine-string-policy-for-Content-Security-Policy/ta-p/1715491&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.qlik.com/articles/000069349" target="_blank"&gt;https://support.qlik.com/articles/000069349&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I will say that in the field, mistakes with this hardening can sometimes break access to the environment so it is recommended to fully research those implementations and test them in lower environments prior to deploying.&lt;/P&gt;
&lt;P&gt;I hope that helps!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 15:43:06 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/recommended-policy-for-Content-Security-Policy/m-p/2089614#M29702</guid>
      <dc:creator>Jay_Brown</dc:creator>
      <dc:date>2023-06-30T15:43:06Z</dc:date>
    </item>
  </channel>
</rss>

