Force browsers to always use HTTPS

Control which resources can be loaded

Prevent clickjacking attacks

Prevent MIME-type sniffing