Fortinet white logo
Fortinet white logo

Administration Guide

Enhanced Client-Side Protection Dashboard (8.0.3)

Enhanced Client-Side Protection Dashboard (8.0.3)

FortiWeb 8.0.3 introduces a major expansion of the Client-Side Protection dashboard that improves how script activity, browser-collected telemetry, and security header behavior are monitored and reviewed. The underlying data collected from the browser has been extended to include a broader set of resource types, script versions, insights, header comparisons, and alert conditions. To present this information more effectively, the Client-Side Protection dashboard has been reorganized into dedicated pages that separate high-level summaries from detailed operational views. The previous Client-Side Protection dashboard content now appears in the updated Overview page, while new pages for Discovered Scripts, PCI Compliance, Security Headers, and Alert Center provide focused interfaces for analyzing client-side behavior and completing required review and compliance tasks.

Overview (Updated)

The Overview page retains the Client-Side Protection information that was available in earlier releases, where the dashboard provided a high-level, service-oriented view of the third-party domains and resources loaded by client browsers. Administrators can continue to see which external services are being used, how frequently they are accessed, their associated risk levels, and whether they are allowed or blocked under the current Client-Side Protection policy. No functional changes were introduced to this data or workflow in 8.0.3; the page has simply been repositioned within the expanded dashboard to serve as the entry point for Client-Side Protection. All new script-level tracking, version history, PCI findings, and alert workflows are presented in the additional pages described below.

Discovered Scripts (New)

The Discovered Scripts page introduces a unified interface for viewing all script resources identified on protected pages. Both external and inline scripts are listed with expanded metadata such as source page location, insights observed by the JS Collector, hash and version history, and indicators for new scripts, new versions, or newly detected behavior. Inline scripts now include precise line-number positions within the HTML source and support per-script block and unblock actions. Review operations such as applying SRI, editing notes, and marking a script as reviewed are performed directly within this page, creating a central workspace for managing script integrity and behavior.

PCI Compliance (New)

A new PCI Compliance page supports organizations subject to PCI DSS 4.0.1 requirements. Findings collected from the browser are grouped according to the tasks defined in PCI DSS requirements 6.4.3 and 11.6.1, including newly discovered scripts, new script versions, missing notes, security header anomalies, and alert configuration issues. Administrators can configure payment page scope within the Client-Side Protection policy and complete review actions with required notes to ensure proper documentation for audit reporting. A downloadable CSV is available for exporting the full review and change history associated with payment pages.

Security Headers (New)

The Security Headers page reports discrepancies between expected security headers and those observed in the browser. Using values collected by the JS Collector, FortiWeb identifies missing, modified, or unexpected headers for items such as Content-Security-Policy, Referrer-Policy, Permissions-Policy, HSTS, and others. Each finding is displayed for review, allowing administrators to evaluate potential client-side manipulation. This page also supports PCI DSS requirement 11.6.1 by highlighting unauthorized modifications to security-impacting headers.

Alert Center (New)

The Alert Center provides a centralized view of Client-Side Protection-related events detected by FortiWeb. It aggregates information such as newly discovered resources, hash or integrity changes, broken links, new insights, JS injection failures, and security header modification failures. Alerts include timestamps, resource URL, and contextual details, and administrators can filter and review entries directly within the page. This unified alert view improves situational awareness and helps identify client-side anomalies that may indicate tampering or compromised external resources.

Enhanced Client-Side Protection Dashboard (8.0.3)

Enhanced Client-Side Protection Dashboard (8.0.3)

FortiWeb 8.0.3 introduces a major expansion of the Client-Side Protection dashboard that improves how script activity, browser-collected telemetry, and security header behavior are monitored and reviewed. The underlying data collected from the browser has been extended to include a broader set of resource types, script versions, insights, header comparisons, and alert conditions. To present this information more effectively, the Client-Side Protection dashboard has been reorganized into dedicated pages that separate high-level summaries from detailed operational views. The previous Client-Side Protection dashboard content now appears in the updated Overview page, while new pages for Discovered Scripts, PCI Compliance, Security Headers, and Alert Center provide focused interfaces for analyzing client-side behavior and completing required review and compliance tasks.

Overview (Updated)

The Overview page retains the Client-Side Protection information that was available in earlier releases, where the dashboard provided a high-level, service-oriented view of the third-party domains and resources loaded by client browsers. Administrators can continue to see which external services are being used, how frequently they are accessed, their associated risk levels, and whether they are allowed or blocked under the current Client-Side Protection policy. No functional changes were introduced to this data or workflow in 8.0.3; the page has simply been repositioned within the expanded dashboard to serve as the entry point for Client-Side Protection. All new script-level tracking, version history, PCI findings, and alert workflows are presented in the additional pages described below.

Discovered Scripts (New)

The Discovered Scripts page introduces a unified interface for viewing all script resources identified on protected pages. Both external and inline scripts are listed with expanded metadata such as source page location, insights observed by the JS Collector, hash and version history, and indicators for new scripts, new versions, or newly detected behavior. Inline scripts now include precise line-number positions within the HTML source and support per-script block and unblock actions. Review operations such as applying SRI, editing notes, and marking a script as reviewed are performed directly within this page, creating a central workspace for managing script integrity and behavior.

PCI Compliance (New)

A new PCI Compliance page supports organizations subject to PCI DSS 4.0.1 requirements. Findings collected from the browser are grouped according to the tasks defined in PCI DSS requirements 6.4.3 and 11.6.1, including newly discovered scripts, new script versions, missing notes, security header anomalies, and alert configuration issues. Administrators can configure payment page scope within the Client-Side Protection policy and complete review actions with required notes to ensure proper documentation for audit reporting. A downloadable CSV is available for exporting the full review and change history associated with payment pages.

Security Headers (New)

The Security Headers page reports discrepancies between expected security headers and those observed in the browser. Using values collected by the JS Collector, FortiWeb identifies missing, modified, or unexpected headers for items such as Content-Security-Policy, Referrer-Policy, Permissions-Policy, HSTS, and others. Each finding is displayed for review, allowing administrators to evaluate potential client-side manipulation. This page also supports PCI DSS requirement 11.6.1 by highlighting unauthorized modifications to security-impacting headers.

Alert Center (New)

The Alert Center provides a centralized view of Client-Side Protection-related events detected by FortiWeb. It aggregates information such as newly discovered resources, hash or integrity changes, broken links, new insights, JS injection failures, and security header modification failures. Alerts include timestamps, resource URL, and contextual details, and administrators can filter and review entries directly within the page. This unified alert view improves situational awareness and helps identify client-side anomalies that may indicate tampering or compromised external resources.