The Security page allows you to configure settings related to your general security, user password settings, and content security policy. The general security settings that you configure control the security of the browser application itself, such as whether the application can be included in an iframe — such as within the application’s integration with Salesforce.
The user password settings control whether passwords expire, and the strength required for passwords.
The content security policy settings control whether you can use a Content Security Policy (CSP) as an added layer of security to detect and mitigate certain types of attacks, including cross-site scripting and data injection attacks. A policy may enforce a stricter execution mode for JavaScript in order to prevent certain cross-site scripting attacks.