# CSP: treat adoption as a dependency migration

https://thiago.limaesilvatecnologia.com.br/en/artigos/csp-migration/

Published: 2026-09-12

A sustainable policy needs script owners.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: January 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

Adding a restrictive policy without understanding scripts can break functionality. Broadly allowing origins to fix it may undermine the original intent. The decision must involve product owners and suppliers.

## Practical application

Editorial proposal: inventory scripts by function, origin and owner. In a hypothetical checkout, distinguish payments, measurement and support. Plan each dependency's removal or adaptation before moving from observation to enforcement.

## How to verify

Choose a critical journey to monitor and a time-limited rollback. Violation reports are investigation signals, not automatic proof of attack. Aim for a policy the team understands, with justified and reviewable exceptions.

## Sources

- [OWASP — Content Security Policy Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
