The policy directives and their values that CloudFront includes as values for the Content-Security-Policy HTTP response header.
Content-Security-Policy
A Boolean that determines whether CloudFront overrides the Content-Security-Policy HTTP response header received from the origin with the one specified in this response headers policy.